Skip to content

CVE-2025-66021 not detected? #8195

@gbrinkmann

Description

@gbrinkmann

Hi,

I'm wondering why dependency-check-maven (v12.1.0 a.t.m.) doesn't list CVE-2025-66021 for OWASP java-html-sanitizer? Database maintainance and updates in logs look fine.

Note: I'm currently watching OWASP/java-html-sanitizer#364 - the issue might be solved in the near future.

edit, additional note: our dependency-track shows the CVE, but without severity. Maybe this is also dependency-check's problem...

Best regards

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions