Commit 4dedd76
fix: upgrade jsoup to 1.23.2 to address Snyk resource allocation vulnerability
jsoup 1.23.1 is flagged by Snyk (CVE-2026-75140) for unbounded memory
growth in XmlTreeBuilder's namespace scope tracking. Fixed upstream in
1.23.2 via a rewritten NamespaceBindings scope tracker that replaces the
per-element namespace-map copy.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>1 parent 410fc0f commit 4dedd76
2 files changed
Lines changed: 8 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
5 | 11 | | |
6 | 12 | | |
7 | 13 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
0 commit comments