renovate-bot opened a new pull request, #6744: URL: https://github.com/apache/jmeter/pull/6744
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.jsoup:jsoup](https://jsoup.org/) ([source](https://redirect.github.com/jhy/jsoup)) | `1.21.2` → `1.23.1` |  |  | --- ### jsoup: Cleaner may expose markup with custom raw-text elements [CVE-2026-71497](https://nvd.nist.gov/vuln/detail/CVE-2026-71497) / [GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8) <details> <summary>More information</summary> #### Details When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup after serialization and potentially allowing XSS. jsoup’s built-in Safelists are unaffected. ##### Patches Upgrade to jsoup 1.23.1. ##### Workarounds Until upgrading, do not permit raw-text elements in custom Safelists used to clean untrusted HTML. ##### Additional security considerations This fix addresses malformed tag-name handling only. Permitting raw-text elements in a custom `Safelist` does not make their contents inherently safe. For example, applications that permit `style` must apply appropriate CSS safeguards separately, because jsoup does not parse or sanitize CSS. #### Severity - CVSS Score: 4.7 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N` #### References - [https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8) - [https://github.com/jhy/jsoup/issues/2538](https://redirect.github.com/jhy/jsoup/issues/2538) - [https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70](https://redirect.github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70) - [https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1](https://redirect.github.com/jhy/jsoup/releases/tag/jsoup-1.23.1) - [https://github.com/advisories/GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>jhy/jsoup (org.jsoup:jsoup)</summary> ### [`v1.23.1`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1231-2026-Jul-30) ##### Improvements - Reduced retained memory when parsing with source position tracking enabled (`Parser#setTrackPosition(true)`). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and `Position` objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping `Node#sourceRange()`, `Element#endSourceRange()`, and `Attribute#sourceRange()` behavior intact. [#​2498](https://redirect.github.com/jhy/jsoup/pull/2498) - Added `Element#classList()`, an immutable snapshot of an element's class names in attribute order. Use `hasClass()` when you just need to test for one class, `classList()` when you want to read or iterate classes without needing a mutable result, and `classNames()` when you want the existing mutable, deduplicated set that can be written back with `classNames(Set)`. The class APIs now share an HTML-whitespace scanner, which also makes `classNames()` faster and lighter on allocation, especially when walking many elements without class names. [#​2500](https://redirect.github.com/jhy/jsoup/pull/2500) - Aligned HTML parser scope classification with the current HTML spec for `select`, `foreignObject`, and `template`. [#​2501](https://redirect.github.com/jhy/jsoup/issues/2501) - Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. [#​2502](https://redirect.github.com/jhy/jsoup/issues/2502) - Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. [#​2507](https://redirect.github.com/jhy/jsoup/pull/2507) - `<noscript>` fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. [#​2537](https://redirect.github.com/jhy/jsoup/pull/2537) - Improved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a `CookieStore` continue to follow their configured scope. [#​2540](https://redirect.github.com/jhy/jsoup/pull/2540) - Elements can now append their outer HTML, including their own tags, directly to an `Appendable` with `Node#outerHtml(Appendable)`, without first creating a `String`. This complements `Element#html(Appendable)`, which appends inner HTML only. [#​2532](https://redirect.github.com/jhy/jsoup/issues/2532) - Aligned CDATA tokenization with the HTML spec: CDATA syntax in HTML content is parsed as a bogus comment, while it remains supported in SVG, MathML, and XML. Also improved namespace-aware fragment parsing so SVG and MathML contexts, HTML integration points, and context-sensitive tokenizer states are handled correctly. [#​2542](https://redirect.github.com/jhy/jsoup/issues/2542) - When using the optional `re2j` regular expression engine, stack overflows caused by complex selector patterns are now normalized to a `ValidationException` with a `Pattern complexity error` message. [#​2548](https://redirect.github.com/jhy/jsoup/issues/2548) ##### Bug Fixes - Fixed HTML parsing of mixed-case RCDATA end tags after tag-shaped text. For example, `<title><p>Foo</TiTLE>` and `<textarea><img src=x></TeXtArEa>` now keep the tag-shaped content as text instead of promoting it to markup. [#​2503](https://redirect.github.com/jhy/jsoup/issues/2503) - Fixed `W3CDom` XML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces and `xml:*` attributes are still preserved. [#​2504](https://redirect.github.com/jhy/jsoup/issues/2504) - Preserve control characters in parsed tag names [#​2538](https://redirect.github.com/jhy/jsoup/issues/2538) - Updated HTTP redirects to follow the specification: 307 and 308 preserve the request method and content, 301 and 302 only change POST to GET, and `Location` is followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. [#​2540](https://redirect.github.com/jhy/jsoup/pull/2540) - Corrected the Cleaner's same-site link detection to compare hostnames rather than URL prefixes when applying `rel=nofollow`. [#​2543](https://redirect.github.com/jhy/jsoup/issues/2543) ##### Build Changes - Cleaned up the Maven build for the multi-release JAR so Java 8 and Java 11+ sources compile as separate source sets. This avoids spurious Java 8 compiler warnings from newer-language overlay sources, keeps long-running parser checks behind an explicit profile, and preserves the same published artifacts and runtime behavior. - Improved parallelism and tuned timing in our integration tests, so that a full `mvn clean verify` drops from \~ 1m18s to \~ 21 seconds. ### [`v1.22.2`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1222-2026-Apr-20) ##### Improvements - Expanded and clarified `NodeTraversor` support for in-place DOM rewrites during `NodeVisitor.head()`. Current-node edits such as `remove`, `replace`, and `unwrap` now recover more predictably, while traversal stays within the original root subtree. This makes single-pass tree cleanup and normalization visitors easier to write, for example when unwrapping presentational elements or replacing text nodes as you walk the DOM. [#​2472](https://redirect.github.com/jhy/jsoup/issues/2472) - Documentation: clarified that a configured `Cleaner` may be reused across concurrent threads, and that shared `Safelist` instances should not be mutated while in use. [#​2473](https://redirect.github.com/jhy/jsoup/issues/2473) - Updated the default HTML `TagSet` for current HTML elements: added `dialog`, `search`, `picture`, and `slot`; made `ins`, `del`, `button`, `audio`, `video`, and `canvas` inline by default (`Tag#isInline()`, aligned to phrasing content in the spec); and added readable `Element.text()` boundaries for controls and embedded objects via the new `Tag.TextBoundary` option. This improves pretty-printing and keeps normalized text from running adjacent words together. [#​2493](https://redirect.github.com/jhy/jsoup/pull/2493) ##### Bug Fixes - Android (R8/ProGuard): added a rule to ignore the optional `re2j` dependency when not present. [#​2459](https://redirect.github.com/jhy/jsoup/issues/2459) - Fixed a `NodeTraversor` regression in 1.21.2 where removing or replacing the current node during `head()` could revisit the replacement node and loop indefinitely. The traversal docs now also clarify which inserted nodes are visited in the current pass. [#​2472](https://redirect.github.com/jhy/jsoup/issues/2472) - Parsing during charset sniffing no longer fails if an advisory `available()` call throws `IOException`, as seen on JDK 8 `HttpURLConnection`. [#​2474](https://redirect.github.com/jhy/jsoup/issues/2474) - `Cleaner` no longer makes relative URL attributes in the input document absolute when cleaning or validating a `Document`. URL normalization now applies only to the cleaned output, and `Safelist.isSafeAttribute()` is side effect free. [#​2475](https://redirect.github.com/jhy/jsoup/issues/2475) - `Cleaner` no longer duplicates enforced attributes when the input `Document` preserves attribute case. A case-variant source attribute is now replaced by the enforced attribute in the cleaned output. [#​2476](https://redirect.github.com/jhy/jsoup/issues/2476) - If a per-request SOCKS proxy is configured, jsoup now avoids using the JDK `HttpClient`, because the JDK would silently ignore that proxy and attempt to connect directly. Those requests now fall back to the legacy `HttpURLConnection` transport instead, which does support SOCKS. [#​2468](https://redirect.github.com/jhy/jsoup/issues/2468) - `Connection.Response.streamParser()` and `DataUtil.streamParser(Path, ...)` could fail on small inputs without a declared charset, if the initial 5 KB charset sniff fully consumed the input and closed it before the stream parse began. [#​2483](https://redirect.github.com/jhy/jsoup/issues/2483) - In XML mode, doctypes with an internal subset, such as `<!DOCTYPE root [<!ENTITY name "value">]>`, now round-trip correctly. The subset is preserved as raw text only; entities are not expanded and external DTDs are not loaded. [#​2486](https://redirect.github.com/jhy/jsoup/issues/2486) ##### Build Changes - Migrated the integration test server from Jetty to Netty, which actively maintains support for our minimum JDK target (8). [#​2491](https://redirect.github.com/jhy/jsoup/pull/2491) ### [`v1.22.1`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1221-2026-Jan-01) ##### Improvements - Added support for using the `re2j` regular expression engine for regex-based CSS selectors (e.g. `[attr~=regex]`, `:matches(regex)`), which ensures linear-time performance for regex evaluation. This allows safer handling of arbitrary user-supplied query regexes. To enable, add the `com.google.re2j` dependency to your classpath, e.g.: ```xml <dependency> <groupId>com.google.re2j</groupId> <artifactId>re2j</artifactId> <version>1.8</version> </dependency> ``` (If you already have that dependency in your classpath, but you want to keep using the Java regex engine, you can disable re2j via `System.setProperty("jsoup.useRe2j", "false")`.) You can confirm that the re2j engine has been enabled correctly by calling `org.jsoup.helper.Regex.usingRe2j()`. [#​2407](https://redirect.github.com/jhy/jsoup/pull/2407) - Added an instance method `Parser#unescape(String, boolean)` that unescapes HTML entities using the parser's configuration (e.g. to support error tracking), complementing the existing static utility `Parser.unescapeEntities(String, boolean)`. [#​2396](https://redirect.github.com/jhy/jsoup/pull/2396) - Added a configurable maximum parser depth (to limit the number of open elements on stack) to both HTML and XML parsers. The HTML parser now defaults to a depth of 512 to match browser behavior, and protect against unbounded stack growth, while the XML parser keeps unlimited depth by default, but can opt into a limit via `org.jsoup.parser.Parser#setMaxDepth`. [#​2421](https://redirect.github.com/jhy/jsoup/issues/2421) - Build: added CI coverage for JDK 25 [#​2403](https://redirect.github.com/jhy/jsoup/pull/2403) - Build: added a CI fuzzer for contextual fragment parsing (in addition to existing full body HTML and XML fuzzers). [oss-fuzz #​14041](https://redirect.github.com/google/oss-fuzz/pull/14041) ##### Changes - Set a removal schedule of jsoup 1.24.1 for previously deprecated APIs. ##### Bug Fixes - Previously cached child `Elements` of an `Element` were not correctly invalidated in `Node#replaceWith(Node)`, which could lead to incorrect results when subsequently calling `Element#children()`. [#​2391](https://redirect.github.com/jhy/jsoup/issues/2391) - Attribute selector values are now compared literally without trimming. Previously, jsoup trimmed whitespace from selector values and from element attribute values, which could cause mismatches with browser behavior (e.g. `[attr=" foo "]`). Now matches align with the CSS specification and browser engines. [#​2380](https://redirect.github.com/jhy/jsoup/issues/2380) - When using the JDK HttpClient, any system default proxy (`ProxySelector.getDefault()`) was ignored. Now, the system proxy is used if a per-request proxy is not set. [#​2388](https://redirect.github.com/jhy/jsoup/issues/2388), [#​2390](https://redirect.github.com/jhy/jsoup/pull/2390) - A `ValidationException` could be thrown in the adoption agency algorithm with particularly broken input. Now logged as a parse error. [#​2393](https://redirect.github.com/jhy/jsoup/issues/2393) - Null characters in the HTML body were not consistently removed; and in foreign content were not correctly replaced. [#​2395](https://redirect.github.com/jhy/jsoup/issues/2395) - An `IndexOutOfBoundsException` could be thrown when parsing a body fragment with crafted input. Now logged as a parse error. [#​2397](https://redirect.github.com/jhy/jsoup/issues/2397), [#​2406](https://redirect.github.com/jhy/jsoup/issues/2406) - When using StructuralEvaluators (e.g., a `parent child` selector) across many retained threads, their memoized results could also be retained, increasing memory use. These results are now cleared immediately after use, reducing overall memory consumption. [#​2411](https://redirect.github.com/jhy/jsoup/issues/2411) - Cloning a `Parser` now preserves any custom `TagSet` applied to the parser. [#​2422](https://redirect.github.com/jhy/jsoup/issues/2422), [#​2423](https://redirect.github.com/jhy/jsoup/pull/2423) - Custom tags marked as `Tag.Void` now parse and serialize like the built-in void elements: they no longer consume following content, and the XML serializer emits the expected self-closing form. [#​2425](https://redirect.github.com/jhy/jsoup/issues/2425) - The `<br>` element is once again classified as an inline tag (`Tag.isBlock() == false`), matching common developer expectations and its role as phrasing content in HTML, while pretty-printing and text extraction continue to treat it as a line break in the rendered output. [#​2387](https://redirect.github.com/jhy/jsoup/issues/2387), [#​2439](https://redirect.github.com/jhy/jsoup/issues/2439) - Fixed an intermittent truncation issue when fetching and parsing remote documents via `Jsoup.connect(url).get()`. On responses without a charset header, the initial charset sniff could sometimes (depending on buffering / `available()` behavior) be mistaken for end-of-stream and a partial parse reused, dropping trailing content. [#​2448](https://redirect.github.com/jhy/jsoup/issues/2448) - `TagSet` copies no longer mutate their template during lazy lookups, preventing cross-thread `ConcurrentModificationException` when parsing with shared sessions. [#​2453](https://redirect.github.com/jhy/jsoup/pull/2453) - Fixed parsing of `<svg>` `foreignObject` content nested within a `<p>`, which could incorrectly move the HTML subtree outside the SVG. [#​2452](https://redirect.github.com/jhy/jsoup/issues/2452) ##### Internal Changes - Deprecated internal helper `org.jsoup.internal.Functions` (for removal in v1.23.1). This was previously used to support older Android API levels without full `java.util.function` coverage; jsoup now requires core library desugaring so this indirection is no longer necessary. [#​2412](https://redirect.github.com/jhy/jsoup/pull/2412) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. â™» **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/jmeter). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
