Htmlunit
This hub aggregates every CVE we track for Htmlunit, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librarieslibrary
6
CVEs tracked
2
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Htmlunit.
- CVE-2023-49093HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL9.8
- CVE-2023-2798Denial of service in HtmlUnit7.5
- CVE-2023-26119Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.9.8
- CVE-2022-29546HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption...7.5
- CVE-2022-28366Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit...7.5
- CVE-2020-5529HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. ...8.1
Product normalization is registry-driven with AI assist and human review. How it works