HIGHCVSS 7.5Vulnerability

CVE-2026-75140

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
7.5
retrieved_at
2026-09-25T15:10:02+00:00
score
7.5
last_source
NVD
cve_id
CVE-2026-75140
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-25T15:10:02+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-20T16:18:02.030
last_modified
2026-09-24T20:02:50.260

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Allocation of Resources Without Limits or Throttling

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75140 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal