Hi, The following vulnerability was published for jsoup. Note I'm making this RC leve as we have the same version present in bookworm, trixie, forky and sid. For forky this should thus be defintively RC to make sure we move to a newer upstream version? CVE-2026-71497[0]: | jsoup is a Java library for working with real-world HTML. From | 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a | malformed tag name ending in a control character, causing the tag to | acquire the parsing behavior of a different element. When a custom | Safelist permits certain raw-text elements, this misparsing can | cause content that should remain inert text to be emitted as active | markup after serialization, potentially resulting in cross-site | scripting. jsoup's built-in Safelists are not affected. This issue | is fixed in version 1.23.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-71497 https://www.cve.org/CVERecord?id=CVE-2026-71497 [1] https://github.com/jhy/jsoup/issues/2538 [2] https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8 [4] https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
jsoup, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143906@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Emmanuel Bourg <ebourg@apache.org> (supplier of updated jsoup package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 18 Sep 2026 22:56:10 +0200
Source: jsoup
Architecture: source
Version: 1.23.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg@apache.org>
Closes: 1143906 1144972
Changes:
jsoup (1.23.2-1) unstable; urgency=medium
.
* New upstream release
- Fixes CVE-2026-71497 (Closes: #1143906)
- Fixes CVE-2026-75140 (Closes: #1144972)
- Updated the Files-Excluded patterns for the non-free test files
- Build depend on libnetty-java instead of libjetty9-java, upstream
moved its test server to netty
- New build dependencies on libbuild-helper-maven-plugin-java,
libjspecify-java and libre2j-java
- Ignored the central-publishing-maven-plugin
- Added a patch for compatibility with JUnit 5.10
- Added a patch for compatibility with netty 4.1
* Removed the libjsoup-java-doc package
* Modernised debian/watch and switched it to version 5
* Standards-Version updated to 4.7.4
Checksums-Sha1:
10e835cdd2c0a1f6ef5008d24f3a87bdeec54de4 2206 jsoup_1.23.2-1.dsc
b118118fe873615be4cf358e05e7acdabd87d616 579760 jsoup_1.23.2.orig.tar.xz
1bc5d05d69aa40308fab10bfb7b3dad788b89170 6896 jsoup_1.23.2-1.debian.tar.xz
dc0addcc6fecd6d10fc99a75d92811bff435f526 15872 jsoup_1.23.2-1_source.buildinfo
Checksums-Sha256:
258a49a4896cad0fa80c60c749a2984129621df2caed26c1211925bd8f964e74 2206 jsoup_1.23.2-1.dsc
92efc7c6bb4480b5411302df0c2041b2680a9b35a01532c29e86b319e74a32b6 579760 jsoup_1.23.2.orig.tar.xz
7cc30887d8007c013d5281828f81ed51a76a462075bd65434308dac04de70efc 6896 jsoup_1.23.2-1.debian.tar.xz
545c8bb42159ae171b89b6819af748c0ecd45d4004b08283f2300b052f6cdc7b 15872 jsoup_1.23.2-1_source.buildinfo
Files:
ecfea7e6b71a9b7bd3a2b8301131b68b 2206 java optional jsoup_1.23.2-1.dsc
5bb1e5ffcf256b37a2b8704356f53997 579760 java optional jsoup_1.23.2.orig.tar.xz
9cf8ef498eb4313038bb0dc38fbab5de 6896 java optional jsoup_1.23.2-1.debian.tar.xz
0f5dfba862ce7875d8d34ac924cfcd1e 15872 java optional jsoup_1.23.2-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmqtq2sSHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCs3FAP/26feIr6pHTKvcI5hUVasIhiNL+OHtZ0
jHRg8XGkKGI1a7Ar8SJTNv597427rpqz2mQk0Ajway7x5Y/sbHHSQ4wS6gHKd077
E3NDOFaSkyVE8TeFnmd5OFOQevHxKMcg5b9MbdCATvm0RmD9aNmKUBYo54I7ifH4
Pq+Vds+0ah0I85BDWoKqNXV72kHxsvmbCCcwVOkpOdc/mVdLGrmgyh5/ugimCUqm
QGBONoLF4nu6BHsU2jjoppq21oP6rnmyA3dcDYDAWux4fcU7KOkSMXW1z2h21CUr
LS2QFFJZZIXMunJUPI7WjG579QXOZL3ZWT0K7IUTRaWc7mQUOGc963N13a0LgPwc
xL148V7AJY6nwirqvQOtiQBGQNbfTuyiwX/b2Iz1sVeK3jcu0Dn+l5G4BsWNsXOI
cuKYS7HnxeBtTr+OM0WS5KLhl88nxZ+4vfNXghUmE+dGSmV3fx6w7gG5qt34rsSC
Yqt9RxCyOqv/1NiMfS/8Z2YMdcaBZxh1s4dl/602nsJB01298qYcs9trm6//aHw1
PDbP5d7rUUXVU7LbRNaa653Rq9niNCoVj9vVnyPupM+KujXXf8LAgKButNUFAPIo
YJrfypMmoNDlTF8qf5Dd9BJzc4KZvpX/4ErvrHgHV7Ewj31loS8lVGdnZUWvD5Vg
846UYAkh4peO
=3uhI
-----END PGP SIGNATURE-----