jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jsoup-javadocUpgrade jsoup | Apr 2, 2025 | Aug 18, 2021 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Nov 21, 2023 |
| Debian | — | Upgrade jsoup | Jul 30, 2024 | Aug 18, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Aug 18, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Aug 18, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 18, 2021 |
| Suse | — | Upgrade jsr-305Upgrade jsoupUpgrade jsr-305-javadocUpgrade jsoup-javadoc | Oct 26, 2022 | Aug 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub