{"id":"CVE-2022-29546","details":"HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.","aliases":["GHSA-6jmm-mp6w-4rrg"],"modified":"2026-08-12T03:51:13.018287444Z","published":"2022-04-25T02:54:59Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29546.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29546.json"},{"type":"ADVISORY","url":"https://github.com/HtmlUnit/htmlunit-neko/security/advisories/GHSA-6jmm-mp6w-4rrg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29546"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/htmlunit/htmlunit","events":[{"introduced":"0"},{"fixed":"ad5208c22fda11c065330f7ba2dd97a89a1a0371"}],"database_specific":{"cpe":"cpe:2.3:a:htmlunit:htmlunit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.61.0"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/htmlunit/htmlunit-neko","events":[{"introduced":"0"},{"fixed":"f06a78ef92baee41313a29c086a520edf71d05a9"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"2.61.0"}]}}],"versions":["2.60.0","2.59.0","2.58.0","2.57.0","2.56.0","2.55.0","2.54.0","2.53.0","2.52.0","2.51.0","2.50.0","2.49.1","2.49.0","2.48.0","2.47.1","2.47.0","2.46.0","2.45.0","2.44.0","2.43.0","2.42.0","2.41.0","2.39.0","2.38.0","2.37.0","2.36.0","2.35.0","2.34.1","2.34.0","2.33","2.32","1.34.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29546.json"}}],"schema_version":"1.9.0"}