renovate-bot opened a new pull request, #6744:
URL: https://github.com/apache/jmeter/pull/6744

   This PR contains the following updates:
   
   | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | 
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
   |---|---|---|---|
   | [org.jsoup:jsoup](https://jsoup.org/) 
([source](https://redirect.github.com/jhy/jsoup)) | `1.21.2` → `1.23.1` | 
![age](https://developer.mend.io/api/mc/badges/age/maven/org.jsoup:jsoup/1.23.1?slim=true)
 | 
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.jsoup:jsoup/1.21.2/1.23.1?slim=true)
 |
   
   ---
   
   ### jsoup: Cleaner may expose markup with custom raw-text elements
   [CVE-2026-71497](https://nvd.nist.gov/vuln/detail/CVE-2026-71497) / 
[GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   When a custom `Safelist` permits certain raw-text elements, jsoup may 
incorrectly sanitize malformed HTML containing a tag name that ends in a 
control character. The tag may acquire the parsing behavior of a different 
element, causing content that should remain text to be emitted as active markup 
after serialization and potentially allowing XSS.
   
   jsoup’s built-in Safelists are unaffected.
   
   ##### Patches
   
   Upgrade to jsoup 1.23.1.
   
   ##### Workarounds
   
   Until upgrading, do not permit raw-text elements in custom Safelists used to 
clean untrusted HTML.
   
   ##### Additional security considerations
   
   This fix addresses malformed tag-name handling only.
   
   Permitting raw-text elements in a custom `Safelist` does not make their 
contents inherently safe. For example, applications that permit `style` must 
apply appropriate CSS safeguards separately, because jsoup does not parse or 
sanitize CSS.
   
   #### Severity
   - CVSS Score: 4.7 / 10 (Medium)
   - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N`
   
   #### References
   - 
[https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8)
   - 
[https://github.com/jhy/jsoup/issues/2538](https://redirect.github.com/jhy/jsoup/issues/2538)
   - 
[https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70](https://redirect.github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70)
   - 
[https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1](https://redirect.github.com/jhy/jsoup/releases/tag/jsoup-1.23.1)
   - 
[https://github.com/advisories/GHSA-pmhh-3w7g-xqp8](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8)
   
   This data is provided by the [GitHub Advisory 
Database](https://redirect.github.com/advisories/GHSA-pmhh-3w7g-xqp8) ([CC-BY 
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
   </details>
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>jhy/jsoup (org.jsoup:jsoup)</summary>
   
   ### 
[`v1.23.1`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1231-2026-Jul-30)
   
   ##### Improvements
   
   - Reduced retained memory when parsing with source position tracking enabled 
(`Parser#setTrackPosition(true)`). Source ranges are now stored in compact 
parser-owned span records instead of node and attribute user data, and 
`Position` objects are created lazily when source ranges are read. This cuts 
tracked DOM retained size by about 50-60% on representative benchmark 
documents, while keeping `Node#sourceRange()`, `Element#endSourceRange()`, and 
`Attribute#sourceRange()` behavior intact. 
[#&#8203;2498](https://redirect.github.com/jhy/jsoup/pull/2498)
   - Added `Element#classList()`, an immutable snapshot of an element's class 
names in attribute order. Use `hasClass()` when you just need to test for one 
class, `classList()` when you want to read or iterate classes without needing a 
mutable result, and `classNames()` when you want the existing mutable, 
deduplicated set that can be written back with `classNames(Set)`. The class 
APIs now share an HTML-whitespace scanner, which also makes `classNames()` 
faster and lighter on allocation, especially when walking many elements without 
class names. [#&#8203;2500](https://redirect.github.com/jhy/jsoup/pull/2500)
   - Aligned HTML parser scope classification with the current HTML spec for 
`select`, `foreignObject`, and `template`. 
[#&#8203;2501](https://redirect.github.com/jhy/jsoup/issues/2501)
   - Simplified the HTML tree builder's scope, implied-end-tag, and 
special-element checks by caching parser-only options on Tag. That improves 
HTML parser throughput by about 10% on small inputs and up to about 30% on 
larger inputs in the benchmark fixtures. 
[#&#8203;2502](https://redirect.github.com/jhy/jsoup/issues/2502)
   - Improved HTML parser throughput stability by making hot tokeniser scan 
paths compile more predictably. 
[#&#8203;2507](https://redirect.github.com/jhy/jsoup/pull/2507)
   - `<noscript>` fallback markup is now parsed into an inspectable DOM subtree 
in both the document head and body. The fallback acts as a contained parsing 
island, so malformed markup cannot disrupt the surrounding document structure, 
while normal HTML tokenization still applies within it. This also improves 
round-trip serialization. 
[#&#8203;2537](https://redirect.github.com/jhy/jsoup/pull/2537)
   - Improved redirect credential handling as a defense-in-depth measure: 
explicit authorization headers and request cookies are no longer forwarded 
across origins, reducing exposure through open redirects and aligning with HTTP 
guidance. Cookies managed by a `CookieStore` continue to follow their 
configured scope. 
[#&#8203;2540](https://redirect.github.com/jhy/jsoup/pull/2540)
   - Elements can now append their outer HTML, including their own tags, 
directly to an `Appendable` with `Node#outerHtml(Appendable)`, without first 
creating a `String`. This complements `Element#html(Appendable)`, which appends 
inner HTML only. 
[#&#8203;2532](https://redirect.github.com/jhy/jsoup/issues/2532)
   - Aligned CDATA tokenization with the HTML spec: CDATA syntax in HTML 
content is parsed as a bogus comment, while it remains supported in SVG, 
MathML, and XML. Also improved namespace-aware fragment parsing so SVG and 
MathML contexts, HTML integration points, and context-sensitive tokenizer 
states are handled correctly. 
[#&#8203;2542](https://redirect.github.com/jhy/jsoup/issues/2542)
   - When using the optional `re2j` regular expression engine, stack overflows 
caused by complex selector patterns are now normalized to a 
`ValidationException` with a `Pattern complexity error` message. 
[#&#8203;2548](https://redirect.github.com/jhy/jsoup/issues/2548)
   
   ##### Bug Fixes
   
   - Fixed HTML parsing of mixed-case RCDATA end tags after tag-shaped text. 
For example, `<title><p>Foo</TiTLE>` and `<textarea><img src=x></TeXtArEa>` now 
keep the tag-shaped content as text instead of promoting it to markup. 
[#&#8203;2503](https://redirect.github.com/jhy/jsoup/issues/2503)
   - Fixed `W3CDom` XML conversion so plain XML elements don't serialize with 
the reserved XML namespace as the default namespace. Explicit XML namespaces 
and `xml:*` attributes are still preserved. 
[#&#8203;2504](https://redirect.github.com/jhy/jsoup/issues/2504)
   - Preserve control characters in parsed tag names 
[#&#8203;2538](https://redirect.github.com/jhy/jsoup/issues/2538)
   - Updated HTTP redirects to follow the specification: 307 and 308 preserve 
the request method and content, 301 and 302 only change POST to GET, and 
`Location` is followed only for 301, 302, 303, 307, and 308 responses. Streamed 
request bodies are not buffered; if an automatic redirect requires replaying 
one, execution fails, so the caller can resend with a fresh stream. 
[#&#8203;2540](https://redirect.github.com/jhy/jsoup/pull/2540)
   - Corrected the Cleaner's same-site link detection to compare hostnames 
rather than URL prefixes when applying `rel=nofollow`. 
[#&#8203;2543](https://redirect.github.com/jhy/jsoup/issues/2543)
   
   ##### Build Changes
   
   - Cleaned up the Maven build for the multi-release JAR so Java 8 and Java 
11+ sources compile as separate source sets. This avoids spurious Java 8 
compiler warnings from newer-language overlay sources, keeps long-running 
parser checks behind an explicit profile, and preserves the same published 
artifacts and runtime behavior.
   - Improved parallelism and tuned timing in our integration tests, so that a 
full `mvn clean verify` drops from \~ 1m18s to \~ 21 seconds.
   
   ### 
[`v1.22.2`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1222-2026-Apr-20)
   
   ##### Improvements
   
   - Expanded and clarified `NodeTraversor` support for in-place DOM rewrites 
during `NodeVisitor.head()`. Current-node edits such as `remove`, `replace`, 
and `unwrap` now recover more predictably, while traversal stays within the 
original root subtree. This makes single-pass tree cleanup and normalization 
visitors easier to write, for example when unwrapping presentational elements 
or replacing text nodes as you walk the DOM. 
[#&#8203;2472](https://redirect.github.com/jhy/jsoup/issues/2472)
   - Documentation: clarified that a configured `Cleaner` may be reused across 
concurrent threads, and that shared `Safelist` instances should not be mutated 
while in use. [#&#8203;2473](https://redirect.github.com/jhy/jsoup/issues/2473)
   - Updated the default HTML `TagSet` for current HTML elements: added 
`dialog`, `search`, `picture`, and `slot`; made `ins`, `del`, `button`, 
`audio`, `video`, and `canvas` inline by default (`Tag#isInline()`, aligned to 
phrasing content in the spec); and added readable `Element.text()` boundaries 
for controls and embedded objects via the new `Tag.TextBoundary` option. This 
improves pretty-printing and keeps normalized text from running adjacent words 
together. [#&#8203;2493](https://redirect.github.com/jhy/jsoup/pull/2493)
   
   ##### Bug Fixes
   
   - Android (R8/ProGuard): added a rule to ignore the optional `re2j` 
dependency when not present. 
[#&#8203;2459](https://redirect.github.com/jhy/jsoup/issues/2459)
   - Fixed a `NodeTraversor` regression in 1.21.2 where removing or replacing 
the current node during `head()` could revisit the replacement node and loop 
indefinitely. The traversal docs now also clarify which inserted nodes are 
visited in the current pass. 
[#&#8203;2472](https://redirect.github.com/jhy/jsoup/issues/2472)
   - Parsing during charset sniffing no longer fails if an advisory 
`available()` call throws `IOException`, as seen on JDK 8 `HttpURLConnection`. 
[#&#8203;2474](https://redirect.github.com/jhy/jsoup/issues/2474)
   - `Cleaner` no longer makes relative URL attributes in the input document 
absolute when cleaning or validating a `Document`. URL normalization now 
applies only to the cleaned output, and `Safelist.isSafeAttribute()` is side 
effect free. [#&#8203;2475](https://redirect.github.com/jhy/jsoup/issues/2475)
   - `Cleaner` no longer duplicates enforced attributes when the input 
`Document` preserves attribute case. A case-variant source attribute is now 
replaced by the enforced attribute in the cleaned output. 
[#&#8203;2476](https://redirect.github.com/jhy/jsoup/issues/2476)
   - If a per-request SOCKS proxy is configured, jsoup now avoids using the JDK 
`HttpClient`, because the JDK would silently ignore that proxy and attempt to 
connect directly. Those requests now fall back to the legacy 
`HttpURLConnection` transport instead, which does support SOCKS. 
[#&#8203;2468](https://redirect.github.com/jhy/jsoup/issues/2468)
   - `Connection.Response.streamParser()` and `DataUtil.streamParser(Path, 
...)` could fail on small inputs without a declared charset, if the initial 5 
KB charset sniff fully consumed the input and closed it before the stream parse 
began. [#&#8203;2483](https://redirect.github.com/jhy/jsoup/issues/2483)
   - In XML mode, doctypes with an internal subset, such as `<!DOCTYPE root 
[<!ENTITY name "value">]>`, now round-trip correctly. The subset is preserved 
as raw text only; entities are not expanded and external DTDs are not loaded. 
[#&#8203;2486](https://redirect.github.com/jhy/jsoup/issues/2486)
   
   ##### Build Changes
   
   - Migrated the integration test server from Jetty to Netty, which actively 
maintains support for our minimum JDK target (8). 
[#&#8203;2491](https://redirect.github.com/jhy/jsoup/pull/2491)
   
   ### 
[`v1.22.1`](https://redirect.github.com/jhy/jsoup/blob/HEAD/CHANGES.md#1221-2026-Jan-01)
   
   ##### Improvements
   
   - Added support for using the `re2j` regular expression engine for 
regex-based CSS selectors (e.g. `[attr~=regex]`, `:matches(regex)`), which 
ensures linear-time performance for regex evaluation. This allows safer 
handling of arbitrary user-supplied query regexes. To enable, add the 
`com.google.re2j` dependency to your classpath, e.g.:
   
   ```xml
     <dependency>
       <groupId>com.google.re2j</groupId>
       <artifactId>re2j</artifactId>
       <version>1.8</version>
     </dependency>
   ```
   
   (If you already have that dependency in your classpath, but you want to keep 
using the Java regex engine, you can disable re2j via 
`System.setProperty("jsoup.useRe2j", "false")`.) You can confirm that the re2j 
engine has been enabled correctly by calling 
`org.jsoup.helper.Regex.usingRe2j()`. 
[#&#8203;2407](https://redirect.github.com/jhy/jsoup/pull/2407)
   
   - Added an instance method `Parser#unescape(String, boolean)` that unescapes 
HTML entities using the parser's configuration (e.g. to support error 
tracking), complementing the existing static utility 
`Parser.unescapeEntities(String, boolean)`. 
[#&#8203;2396](https://redirect.github.com/jhy/jsoup/pull/2396)
   - Added a configurable maximum parser depth (to limit the number of open 
elements on stack) to both HTML and XML parsers. The HTML parser now defaults 
to a depth of 512 to match browser behavior, and protect against unbounded 
stack growth, while the XML parser keeps unlimited depth by default, but can 
opt into a limit via `org.jsoup.parser.Parser#setMaxDepth`. 
[#&#8203;2421](https://redirect.github.com/jhy/jsoup/issues/2421)
   - Build: added CI coverage for JDK 25 
[#&#8203;2403](https://redirect.github.com/jhy/jsoup/pull/2403)
   - Build: added a CI fuzzer for contextual fragment parsing (in addition to 
existing full body HTML and XML fuzzers). [oss-fuzz 
#&#8203;14041](https://redirect.github.com/google/oss-fuzz/pull/14041)
   
   ##### Changes
   
   - Set a removal schedule of jsoup 1.24.1 for previously deprecated APIs.
   
   ##### Bug Fixes
   
   - Previously cached child `Elements` of an `Element` were not correctly 
invalidated in `Node#replaceWith(Node)`, which could lead to incorrect results 
when subsequently calling `Element#children()`. 
[#&#8203;2391](https://redirect.github.com/jhy/jsoup/issues/2391)
   - Attribute selector values are now compared literally without trimming. 
Previously, jsoup trimmed whitespace from selector values and from element 
attribute values, which could cause mismatches with browser behavior (e.g. 
`[attr=" foo "]`). Now matches align with the CSS specification and browser 
engines. [#&#8203;2380](https://redirect.github.com/jhy/jsoup/issues/2380)
   - When using the JDK HttpClient, any system default proxy 
(`ProxySelector.getDefault()`) was ignored. Now, the system proxy is used if a 
per-request proxy is not set. 
[#&#8203;2388](https://redirect.github.com/jhy/jsoup/issues/2388), 
[#&#8203;2390](https://redirect.github.com/jhy/jsoup/pull/2390)
   - A `ValidationException` could be thrown in the adoption agency algorithm 
with particularly broken input. Now logged as a parse error. 
[#&#8203;2393](https://redirect.github.com/jhy/jsoup/issues/2393)
   - Null characters in the HTML body were not consistently removed; and in 
foreign content were not correctly replaced. 
[#&#8203;2395](https://redirect.github.com/jhy/jsoup/issues/2395)
   - An `IndexOutOfBoundsException` could be thrown when parsing a body 
fragment with crafted input. Now logged as a parse error. 
[#&#8203;2397](https://redirect.github.com/jhy/jsoup/issues/2397), 
[#&#8203;2406](https://redirect.github.com/jhy/jsoup/issues/2406)
   - When using StructuralEvaluators (e.g., a `parent child` selector) across 
many retained threads, their memoized results could also be retained, 
increasing memory use. These results are now cleared immediately after use, 
reducing overall memory consumption. 
[#&#8203;2411](https://redirect.github.com/jhy/jsoup/issues/2411)
   - Cloning a `Parser` now preserves any custom `TagSet` applied to the 
parser. [#&#8203;2422](https://redirect.github.com/jhy/jsoup/issues/2422), 
[#&#8203;2423](https://redirect.github.com/jhy/jsoup/pull/2423)
   - Custom tags marked as `Tag.Void` now parse and serialize like the built-in 
void elements: they no longer consume following content, and the XML serializer 
emits the expected self-closing form. 
[#&#8203;2425](https://redirect.github.com/jhy/jsoup/issues/2425)
   - The `<br>` element is once again classified as an inline tag 
(`Tag.isBlock() == false`), matching common developer expectations and its role 
as phrasing content in HTML, while pretty-printing and text extraction continue 
to treat it as a line break in the rendered output. 
[#&#8203;2387](https://redirect.github.com/jhy/jsoup/issues/2387), 
[#&#8203;2439](https://redirect.github.com/jhy/jsoup/issues/2439)
   - Fixed an intermittent truncation issue when fetching and parsing remote 
documents via `Jsoup.connect(url).get()`. On responses without a charset 
header, the initial charset sniff could sometimes (depending on buffering / 
`available()` behavior) be mistaken for end-of-stream and a partial parse 
reused, dropping trailing content. 
[#&#8203;2448](https://redirect.github.com/jhy/jsoup/issues/2448)
   - `TagSet` copies no longer mutate their template during lazy lookups, 
preventing cross-thread `ConcurrentModificationException` when parsing with 
shared sessions. [#&#8203;2453](https://redirect.github.com/jhy/jsoup/pull/2453)
   - Fixed parsing of `<svg>` `foreignObject` content nested within a `<p>`, 
which could incorrectly move the HTML subtree outside the SVG. 
[#&#8203;2452](https://redirect.github.com/jhy/jsoup/issues/2452)
   
   ##### Internal Changes
   
   - Deprecated internal helper `org.jsoup.internal.Functions` (for removal in 
v1.23.1). This was previously used to support older Android API levels without 
full `java.util.function` coverage; jsoup now requires core library desugaring 
so this indirection is no longer necessary. 
[#&#8203;2412](https://redirect.github.com/jhy/jsoup/pull/2412)
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - At any time (no schedule defined)
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   â™» **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   🔕 **Ignore**: Close this PR and you won't be reminded about this update 
again.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR was generated by [Mend Renovate](https://mend.io/renovate/). View 
the [repository job log](https://developer.mend.io/github/apache/jmeter).
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to