CVE-2026-71497

Public on 2026-08-06
Modified on 2026-09-10
Description
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 javapackages-bootstrap Not Affected
Amazon Linux 2027 Preview javapackages-bootstrap Pending Fix
Amazon Linux 2 - Core jsoup Pending Fix
Amazon Linux 2023 jsoup 2026-09-14 ALAS2023-2026-2150 Fixed
Amazon Linux 2027 Preview jsoup Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N