Allocation of Resources Without Limits or Throttling in jsoup - CVE-2026-75140
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the XmlTreeBuilder namespace scope tracking when parsing untrusted XML input. A remote attacker can supply a deeply nested XML document with uniquely named namespace declarations to cause a denial of service.
Parsing documents with many nested namespace bindings grows quadratically in time and retained memory.
Affected software
Crucible Data Center
Crucible Server
How to mitigate CVE-2026-75140
Crucible Data Center - update to 4.9.14
Crucible Server - update to 4.9.14