GHSA-g9hh-vvx3-v37v · Severity: high · Ecosystem: maven — Denial of service in HtmlUnit-Neko
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.
Conclusion & alert: CVE-2022-28366 is rated Moderate Risk (44/100): CVSS High severity, with low exploitation likelihood (EPSS 0.19%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.40% | 0.19% | -0.21% |
| 2 | 2025-11-18 | 0.16% | 0.40% | +0.24% |
| 3 | 2025-09-25 | — | 0.16% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-g9hh-vvx3-v37v · Severity: high · Ecosystem: maven — Denial of service in HtmlUnit-Neko
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-28366 not yet assigned priority: Debian including 1 source packages (libowasp-antisamy-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2. | https://security-tracker.debian.org/tracker/CVE-2022-28366 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2022-28366/ |
ubuntu
|
medium | CVE-2022-28366 medium priority: Ubuntu including 1 source packages (libowasp-antisamy-java), 13 status rows across 13 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, upstream, xenial): needs-triage 7, ignored 6. | https://ubuntu.com/security/CVE-2022-28366 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cyberneko_html_project | cyberneko_html | <= 1.9.22 | cpe:2.3:a:cyberneko_html_project:cyberneko_html:*:*:*:*:*:*:*:* |
| htmlunit | htmlunit | < 2.27 | cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:* |
| antisamy_project | antisamy | < 1.6.6 | cpe:2.3:a:antisamy_project:antisamy:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/nahsra/antisamy/releases/tag/v1.6.6 | Release Notes Third Party Advisory |
| https://search.maven.org/artifact/net.sourceforge.htmlunit/neko-htmlunit | Release Notes Third Party Advisory |
| https://sourceforge.net/projects/htmlunit/files/htmlunit/2.27/ | Release Notes Third Party Advisory |