Hi, The following vulnerability was published for jsoup. CVE-2026-75140[0]: | jsoup through 1.23.2, fixed in commit 862ba2f, contains an | uncontrolled resource consumption vulnerability in XmlTreeBuilder | that allows remote attackers to exhaust JVM heap memory by supplying | a deeply nested XML document with uniquely-namespaced elements. The | builder copies the entire inherited namespace map on every start | element, causing quadratic time and memory complexity, which | attackers can exploit to trigger an OutOfMemoryError and terminate | the application. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-75140 https://www.cve.org/CVERecord?id=CVE-2026-75140 [1] https://github.com/jhy/jsoup/pull/2556 [2] https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a Please adjust the affected versions in the BTS as needed. Regards, Salvatore