A vulnerability being addressed CVE-2022-24839 (BDSA-2022-2705)
The fix is already being provided in https://github.com/sparklemotion/nekohtml/commit/a800fce3b079def130ed42a408ff1d09f89e773d
Please check line 2591
The same fix needs to be provided in net.sourceforge.nekohtml:nekohtml:1.9.22
https://sourceforge.net/p/nekohtml/code/HEAD/tree/branches/nekohtml-1.9.22/src/org/cyberneko/html/HTMLScanner.java#l2591
Please let me know when the fix would be provided.
Thanks
Sourabh