CVE-2022-28366

Source
https://cve.org/CVERecord?id=CVE-2022-28366
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28366.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-28366
Aliases
Downstream
Related
Published
2022-04-21T23:15:10.383Z
Modified
2026-04-02T07:56:03.938092Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.

References

Affected packages

Git / github.com/htmlunit/htmlunit

Affected ranges

Type
GIT
Repo
https://github.com/htmlunit/htmlunit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.27"
        }
    ]
}
Type
GIT
Repo
https://github.com/nahsra/antisamy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.6.6"
        }
    ]
}

Affected versions

1.*
1.6.3
2.*
2.32
2.33
2.34.0
2.34.1
2.35.0
2.36.0
2.37.0
2.38.0
2.39.0
2.39.1
2.40.0
2.41.0
2.42.0
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.47.1
2.48.0
2.49.0
2.49.1
2.50.0
2.51.0
2.52.0
2.53.0
2.54.0
2.55.0
2.56.0
2.57.0
2.58.0
2.59.0
2.60.0
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.66.0
2.67.0
2.68.0
2.69.0
2.70.0
3.*
3.0.0
3.1.0
3.10.0
3.11.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.9.0
4.*
4.0.0
4.1.0
4.10.0
4.11.0
4.11.1
4.12.0
4.13.0
4.14.0
4.15.0
4.16.0
4.17.0
4.18.0
4.19.0
4.2.0
4.20.0
4.21.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0
Other
HtmlUnit-1dot11
HtmlUnit-1dot12
HtmlUnit-1dot13
HtmlUnit-1dot14
HtmlUnit-2.*
HtmlUnit-2.0
HtmlUnit-2.1
HtmlUnit-2.11
HtmlUnit-2.12
HtmlUnit-2.13
HtmlUnit-2.14
HtmlUnit-2.15
HtmlUnit-2.16
HtmlUnit-2.17
HtmlUnit-2.18
HtmlUnit-2.19
HtmlUnit-2.2
HtmlUnit-2.20
HtmlUnit-2.21
HtmlUnit-2.22
HtmlUnit-2.23
HtmlUnit-2.24
HtmlUnit-2.25
HtmlUnit-2.26
HtmlUnit-2.28
HtmlUnit-2.29
HtmlUnit-2.3
HtmlUnit-2.31
HtmlUnit-2.32
HtmlUnit-2.4
HtmlUnit-2.5
HtmlUnit-2.6
HtmlUnit-2.7
HtmlUnit-2.8
HtmlUnit-2.9
v1.*
v1.5.10
v1.5.11
v1.5.12
v1.5.13
v1.5.7
v1.5.8
v1.5.9
v1.6.0
v1.6.1
v1.6.2
v1.6.4
v1.6.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28366.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.9.22"
            }
        ]
    }
]