CVE-2023-51075: Hutool

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.

Affected products

  • Hutool Hutool: before 5.8.24 (fixed in 5.8.24)

Published 2023-12-27. Last modified 2026-06-17.