{"id":"CVE-2022-29577","details":"OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.","aliases":["GHSA-vp37-2f9p-3vr3"],"modified":"2026-08-12T13:01:00.216230Z","published":"2022-04-21T22:42:51Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29577.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/nahsra/antisamy/releases/tag/v1.6.7"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29577.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29577"},{"type":"FIX","url":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nahsra/antisamy","events":[{"introduced":"0"},{"fixed":"a42865ce3956c0e1c8c1993533209d825ff9a19b"},{"fixed":"32e273507da0e964b58c50fd8a4c94c9d9363af0"}],"database_specific":{"cpe":"cpe:2.3:a:antisamy_project:antisamy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.6.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.6.6.1","v1.6.6","v1.6.5","v1.6.4","1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.13","v1.5.12","v1.5.11","v1.5.10","v1.5.9","v1.5.8","v1.5.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29577.json","vanir_signatures_modified":"2026-08-12T13:01:00Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["237853444054347817364515222576269512625","336071599204640059636299145511392624895","165848317299205136683032698194184895651","339101229301899965439775818916251222622","285903785459194626705691651822174438162","231515759940691657940379650850759202754","224156990529132882235418766553590204221"],"threshold":0.9},"id":"CVE-2022-29577-35016ed0","signature_type":"Line","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0","target":{"file":"src/test/java/org/owasp/validator/html/test/AntiSamyTest.java"}},{"id":"CVE-2022-29577-c912ad89","signature_type":"Function","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0","target":{"function":"processStyleTag","file":"src/main/java/org/owasp/validator/html/scan/AntiSamyDOMScanner.java"},"deprecated":false,"digest":{"function_hash":"88131835901757964811327895062350049878","length":1154}},{"target":{"file":"src/test/java/org/owasp/validator/html/test/AntiSamyTest.java","function":"testSmuggledTagsInStyleContent"},"deprecated":false,"digest":{"length":846,"function_hash":"178410271232807830230245771871539052343"},"id":"CVE-2022-29577-ceaa121c","signature_type":"Function","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0"},{"id":"CVE-2022-29577-ebd52f03","signature_type":"Line","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0","target":{"file":"src/main/java/org/owasp/validator/html/scan/AntiSamyDOMScanner.java"},"deprecated":false,"digest":{"line_hashes":["306425877699336243915250815896124374480","82458634497388572929189339455064079514","297848842918691885350402407532356243068","32815047294793109378873259651076730840","273071617774659664431767839626169799535","76571751703142598865683490853200567324","70232678748025585381294938982190700985","328412688529917311588232321115420528786","183962489278164641071475429383934925912","162119904040012907656562718458671386819","186911322794562416845561872734106232305","45862128560471560943951069770339704902","182516468880197479286450933909066344778","131018505150293915404995959334332522954","317605331177973768631118161872046614930","289940291231881362563064475896495769032"],"threshold":0.9}}]}}],"schema_version":"1.9.0"}