Jtidy is a Java HTML parser and tidying library with a narrow product focus, embedded in various downstream applications for document cleanup and validation tasks. Its vulnerability exposure centers on the core Jtidy product and recurs through out-of-bounds write conditions, a pattern characteristic of buffer-handling flaws in parsing code. Current severity, exploitation activity, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jtidy Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34623HIGH An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | Jun 14, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jtidy Project.
Media articles that mention a CVE ID that affects a product developed by Jtidy Project — matched by CVE ID, not by vendor name.