{"id":"GHSA-pmhh-3w7g-xqp8","summary":"jsoup: Cleaner may expose markup with custom raw-text elements","details":"When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup after serialization and potentially allowing XSS.\n\njsoup’s built-in Safelists are unaffected.\n\n## Patches\n\nUpgrade to jsoup 1.23.1.\n\n## Workarounds\n\nUntil upgrading, do not permit raw-text elements in custom Safelists used to clean untrusted HTML.\n\n## Additional security considerations\n\nThis fix addresses malformed tag-name handling only.\n\nPermitting raw-text elements in a custom `Safelist` does not make their contents inherently safe. For example, applications that permit `style` must apply appropriate CSS safeguards separately, because jsoup does not parse or sanitize CSS.","aliases":["CVE-2026-71497"],"modified":"2026-08-06T21:26:12.097711Z","published":"2026-08-06T21:09:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-06T21:09:36Z"},"references":[{"type":"WEB","url":"https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8"},{"type":"WEB","url":"https://github.com/jhy/jsoup/issues/2538"},{"type":"WEB","url":"https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70"},{"type":"PACKAGE","url":"https://github.com/jhy/jsoup"},{"type":"WEB","url":"https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1"}],"affected":[{"package":{"name":"org.jsoup:jsoup","ecosystem":"Maven","purl":"pkg:maven/org.jsoup/jsoup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.14.3"},{"fixed":"1.23.1"}]}],"versions":["1.14.3","1.15.1","1.15.2","1.15.3","1.15.4","1.16.1","1.16.2","1.17.1","1.17.2","1.18.1","1.18.2","1.18.3","1.19.1","1.20.1","1.21.1","1.21.2","1.22.1","1.22.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-pmhh-3w7g-xqp8/GHSA-pmhh-3w7g-xqp8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}