CVE-2025-22872
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 16, 2025
Updated: Apr 17, 2025
Summary
CVE-2025-22872 is a vulnerability affecting the tokenizer in certain contexts. Unquoted attribute values ending with a solidus character (/) in tags are misinterpreted as self-closing, resulting in incorrect markup when using the Tokenizer directly. In the case of Parse functions, the content following such misidentified tags may be placed in the wrong scope during DOM construction. This issue only affects foreign content, such as <math> or <svg> contexts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.