CVE-2022-28366
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.
Algunos analizadores de HTML relacionados con Neko permiten una denegación de servicio a través de una entrada de instrucción de procesamiento (PI) manipulada que provoca un consumo excesivo de memoria de la pila. En particular, este problema existe en HtmlUnit-Neko hasta la versión 2.26, y se ha corregido en la 2.27. Este problema también existe en CyberNeko HTML hasta la versión 1.9.22 (también afecta a OWASP AntiSamy antes de la 1.6.6), pero la 1.9.22 es la última versión de CyberNeko HTML. NOTA: esto puede estar relacionado con CVE-2022-24839
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-03 CVE Reserved
- 2022-04-21 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/nahsra/antisamy/releases/tag/v1.6.6 | Release Notes | |
https://search.maven.org/artifact/net.sourceforge.htmlunit/neko-htmlunit | Release Notes | |
https://sourceforge.net/projects/htmlunit/files/htmlunit/2.27 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cyberneko Html Project Search vendor "Cyberneko Html Project" | Cyberneko Html Search vendor "Cyberneko Html Project" for product "Cyberneko Html" | <= 1.9.22 Search vendor "Cyberneko Html Project" for product "Cyberneko Html" and version " <= 1.9.22" | - |
Affected
| ||||||
Htmlunit Search vendor "Htmlunit" | Htmlunit Search vendor "Htmlunit" for product "Htmlunit" | < 2.27 Search vendor "Htmlunit" for product "Htmlunit" and version " < 2.27" | - |
Affected
| ||||||
Antisamy Project Search vendor "Antisamy Project" | Antisamy Search vendor "Antisamy Project" for product "Antisamy" | < 1.6.6 Search vendor "Antisamy Project" for product "Antisamy" and version " < 1.6.6" | - |
Affected
|