4 jsoup vulnerabilities

· Joshua Rogers · Aug. 11, 2026, 7:53 a.m.
Summary
This blog post discusses vulnerabilities identified in jsoup, specifically focusing on a cleaner HTML-sanitizer bypass that leads to mutation-XSS through MathML namespace confusion. It sheds light on security issues relevant to developers working with jsoup.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →