Get real-time updates on Telegram
CVE-2021-37714: jsoup before 1.14.2 (exclusive), < 1.14.2; +15 more affected products
CVE-2021-37714. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.06689 (percentile 0.93738), scored 2026-10-08.
Affected technology
jsoup · before 1.14.2 (exclusive)
jsoup
quarkus · through 2.2.3 (inclusive)
quarkus
banking trade finance · 14.5
oracle
banking treasury management · 14.5
oracle
business process management suite · 12.2.1.3.0
oracle
business process management suite · 12.2.1.4.0
oracle
flexcube universal banking · from 14.0.0 (inclusive), through 14.3.0 (inclusive)
oracle
flexcube universal banking · 14.5
oracle
hospitality token proxy service · 19.2
oracle
peoplesoft enterprise peopletools · 8.58
oracle
peoplesoft enterprise peopletools · 8.59
oracle
primavera unifier · 20.12
oracle
primavera unifier · 21.12
oracle
retail customer management and segmentation foundation · from 17.0 (inclusive), through 19.0 (inclusive)
oracle
webcenter portal · 12.2.1.3.0
oracle
webcenter portal · 12.2.1.4.0
oracle
communications messaging server · 8.1
oracle
management services for element software and netapp hci · Version not applicable in the source CPE
netapp
financial services crime and compliance management studio · 8.0.8.2.0
oracle
financial services crime and compliance management studio · 8.0.8.3.0
oracle
middleware common libraries and tools · 12.2.1.3.0
oracle
middleware common libraries and tools · 12.2.1.4.0
oracle
stream analytics · before 19.1.0.0.6.4 (exclusive)
oracle
stream analytics · 19c
oracle
jsoup · < 1.14.2
jhy
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source says if the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. Vendor/CNA’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-248, CWE-835
- CCR priority
- 31.7 /100 (P4)
- CVSS 3.1
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.06689 · percentile 0.93738 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-37714.html