HtmlUnit is a lightweight Java-based web client library designed for programmatic HTTP requests and HTML parsing, deployed in security testing, web automation, and integration scenarios where a headless browser alternative is needed. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including code injection, improper initialization, out-of-bounds writes, and uncontrolled resource consumption that reflect the parser and DOM-handling demands of browser simulation. Defenders should treat updates to this library as a patching priority in downstream applications and test infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htmlunit over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26119CRITICAL Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. | Apr 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-29546HIGH HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap m | Apr 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28366HIGH Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue e | Apr 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-2798HIGH Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply co | May 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-49093HIGH HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been | Dec 4, 2023 | 8.8 | 22 | NO | NO |
CVE-2020-5529HIGH HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on | Feb 11, 2020 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htmlunit.
Media articles that mention a CVE ID that affects a product developed by Htmlunit — matched by CVE ID, not by vendor name.