Critical severity9.8OSV Advisory· Published Apr 3, 2023· Updated Jun 17, 2026
CVE-2023-26119
CVE-2023-26119
Description
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.sourceforge.htmlunit:htmlunitMaven | < 3.0.0 | 3.0.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956bnvdPatchWEB
- siebene.github.io/2022/12/30/HtmlUnit-RCE/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-3xrr-7m6p-p7xhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26119ghsaADVISORY
- security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500nvdThird Party AdvisoryWEB
- siebene.github.io/2022/12/30/HtmlUnit-RCEghsaWEB
News mentions
0No linked articles in our index yet.