Allocation of Resources Without Limits or Throttling Affecting jsoup-javadoc package, versions <1.23.2-160000.1.1


Severity

Recommended
0.0
high
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.53% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES1600-JSOUPJAVADOC-20187382
  • published28 Sept 2026
  • disclosed21 Sept 2026

Introduced: 21 Sep 2026

NewCVE-2026-75140  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade SLES:16.0.0 jsoup-javadoc to version 1.23.2-160000.1.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jsoup-javadoc package and not the jsoup-javadoc package as distributed by SLES. See How to fix? for SLES:16.0.0 relevant fixed versions and status.

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.

CVSS Base Scores

version 3.1