CVE-2022-36033: jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled

Published Aug 29, 2022
·
Updated

jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including javascript: URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default SafeList.preserveRelativeLinks option is enabled, HTML including javascript: URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable SafeList.preserveRelativeLinks, which will rewrite input URLs as absolute URLs - ensure an appropriate Content Security Policy is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)

Other sources

jsoup is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

IBM

jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled

Microsoft

Affected Software

11 affected componentsFixes available
jsoup jsoup<1.15.3
NetApp Management Services For Element Software
NetApp Management Services For Netapp Hci
NetApp OnCommand Workflow Automation
IBM Data Virtualization on Cloud Pak for Data<=3.0
IBM Watson Query on Cloud Pak for Data<=2.2
IBM Watson Query on Cloud Pak for Data<=2.1
IBM Watson Query on Cloud Pak for Data<=2.0
IBM Data Virtualization on Cloud Pak for Data<=1.8
IBM Data Virtualization on Cloud Pak for Data<=1.7
Microsoft cbl2 jsoup

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade jsoup to a version that resolves this vulnerability.

    Fixed in 1.15.3
  2. Configuration

    Disable SafeList.preserveRelativeLinks so input URLs are rewritten as absolute URLs (prevents preserving crafted javascript: URLs).

    jsoup SafeList SafeList.preserveRelativeLinks = false
  3. Compensating control

    Ensure an appropriate Content Security Policy (CSP) is defined for the site to mitigate the impact of any unsanitized URLs (defense-in-depth).

  4. Operational

    Re-clean any previously persisted content that may contain unsanitized input using the updated jsoup 1.15.3 to remove potentially malicious javascript: URLs.

Event History

Aug 29, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Sep 15, 2022
Data Sourced
via Red Hat·09:57 AM
DescriptionSeverityAffected Software
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-36033?

CVE-2022-36033 is a vulnerability in the jsoup Java HTML parser that could allow cross-site scripting (XSS) attacks.

2

How does CVE-2022-36033 affect affected software?

CVE-2022-36033 affects jsoup versions up to and excluding 1.15.3, as well as Netapp Management Services For Element Software, Netapp Management Services For Netapp HCI, and NetApp OnCommand Workflow Automation.

3

What is the severity of CVE-2022-36033?

CVE-2022-36033 has a severity rating of medium, with a CVSS score of 6.1.

4

How can I fix CVE-2022-36033?

To fix CVE-2022-36033, update to jsoup version 1.15.3 or later.

5

Where can I find more information about CVE-2022-36033?

You can find more information about CVE-2022-36033 on the jsoup GitHub releases page and the jsoup security advisories page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203