Junglewise Threat Intelligence

CVE-2025-66021: OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

CVE-2025-66021 · Severity: medium · CVSS 4 · Published 2025-11-25

Technologies: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer (Maven). Vendors: Maven.

Executive brief

OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

Affected products

  • Maven com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer

Related threats