First published: Mon Apr 25 2022(Updated: )
HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmlunit Project Htmlunit | <2.61.0 | |
Htmlunit Htmlunit | <2.61.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29546 is a denial of service vulnerability in HtmlUnit NekoHtml Parser before version 2.61.0.
CVE-2022-29546 affects HtmlUnit versions before 2.61.0 and leads to heap memory consumption due to crafted processing instruction (PI) data.
CVE-2022-29546 has a severity level of 7.5 (high).
To fix the CVE-2022-29546 vulnerability, update HtmlUnit to version 2.61.0 or later.
You can find more information about the CVE-2022-29546 vulnerability in the official GitHub security advisory: [CVE-2022-29546](https://github.com/HtmlUnit/htmlunit-neko/security/advisories/GHSA-6jmm-mp6w-4rrg)