SUSE-SU-2026:4393-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264393-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4393-1
Upstream
Related
Published
2026-09-29T11:50:58Z
Modified
2026-09-30T12:00:04Z
Summary
Security update for jsoup, re2j
Details

This update for jsoup, re2j fixes the following issue:

  • CVE-2026-75140: The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application (bsc#1275912).

Changes for jsoup:

  • Upgrade to upstream version 1.23.2
  • Changes of 1.23.2
  • Improvement: Improved consecutive StreamParser.selectFirst() calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given

Full

Next

, selecting title and then #hit now advances the partial lookahead and returns

Full

, rather than returning an empty

before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. + Improvement: Improved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope (bsc#1275912, CVE-2026-75140). + Improvement: Improved W3CDom conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. + Improvement: Improved W3CDom XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. + Improvement: DOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. + Improvement: Added Elements#before(Node), after(Node), prepend(Node), and append(Node) to match the existing HTML string methods. + Improvement: Large file-backed uploads through Connection.requestBodyStream(InputStream) now stream directly with the JDK HttpClient on Java 11+, rather than being loaded fully into memory first. + Improvement: Extended Java 11+ HTTP client reuse from requests sharing a Jsoup.newSession() to ordinary Jsoup.connect() calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. + Change: Aligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use Parser#setMaxDepth(int) to configure. + Bugfix: Fixed W3CDom namespace conversion in several cases: - Namespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected. - Attributes added after parsing, or included through subtree conversion, now use inherited prefix declarations. - Namespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope. - With namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization. - Valid HTML names that are not XML QNames, such as a:b:c, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree. + Bugfix: Fixed W3CDom conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as 1abc. These names are now normalized (e.g. _1abc) instead of causing a NullPointerException. + Bugfix: Fixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. + Bugfix: XML serialization now repairs element and attribute names that start with an invalid character, rather than outputting null elements or dropping attributes. For example, an attribute named 1a is written as _1a. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. + Bugfix: Supplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. + Bugfix: Fixed the JDK HttpClient implementation to accept responses missing a Content-Type header, matching the HttpURLConnection implementation. + Bugfix: Fixed HTTP response content-type matching to handle media types case-insensitively and recognize structured +xml suffixes, including vendor-specific media types. + Bugfix: HTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. + Bugfix: Corrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a ValidationException. + Bugfix: Aligned trailing comment placement with the HTML specification: comments after remain children of the html element, while comments after remain children of the document. + Bugfix: When using the optional re2j regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a ValidationException with a Pattern complexity error message. + Bugfix: Fixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. + Bugfix: Fixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. + Bugfix: Aligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed title/textarea content stays text through EOF, and custom text tags match exact names. + Bugfix: Improved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. + Bugfix: Redirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. + Bugfix: Template fragment parsing now handles unmatched tags without throwing a ValidationException. + Bugfix: Improved source tracking for adopted formatting elements and malformed markup ending at EOF. * Changes of 1.23.1 + Improvement: Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. + Improvement: Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. + Improvement: Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. + Improvement: Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. + Improvement: Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. + Improvement:
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
jsoup

Package

Name
jsoup
Purl
pkg:rpm/suse/jsoup&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.2-150200.3.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "jsoup":  "1.23.2-150200.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4393-1.json"