CVE-2025-22872

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025

Summary

CVE-2025-22872 is a vulnerability affecting the tokenizer in certain contexts. Unquoted attribute values ending with a solidus character (/) in tags are misinterpreted as self-closing, resulting in incorrect markup when using the Tokenizer directly. In the case of Parse functions, the content following such misidentified tags may be placed in the wrong scope during DOM construction. This issue only affects foreign content, such as <math> or <svg> contexts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share