CVE-2022-29546: High severity htmlunit vulnerability
HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29546?
CVE-2022-29546 is a denial of service vulnerability in HtmlUnit NekoHtml Parser before version 2.61.0.
How does CVE-2022-29546 affect HtmlUnit?
CVE-2022-29546 affects HtmlUnit versions before 2.61.0 and leads to heap memory consumption due to crafted processing instruction (PI) data.
What is the severity level of CVE-2022-29546?
CVE-2022-29546 has a severity level of 7.5 (high).
How can I fix the CVE-2022-29546 vulnerability?
To fix the CVE-2022-29546 vulnerability, update HtmlUnit to version 2.61.0 or later.
Where can I find more information about the CVE-2022-29546 vulnerability?
You can find more information about the CVE-2022-29546 vulnerability in the official GitHub security advisory: [CVE-2022-29546](https://github.com/HtmlUnit/htmlunit-neko/security/advisories/GHSA-6jmm-mp6w-4rrg)