THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pmhh-3w7g-xqp8 (medium) — jsoup: Cleaner may expose markup with custom raw-text elements

[GHSA] GHSA-pmhh-3w7g-xqp8 (medium) — jsoup: Cleaner may expose markup with custom raw-text elements

medgithub_advisoriesPublished 2026-08-06

GHSA-pmhh-3w7g-xqp8 Severity: medium CVE: CVE-2026-71497

jsoup: Cleaner may expose markup with custom raw-text elements

When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitt

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pmhh-3w7g-xqp8