diff --git a/SECURITY.md b/SECURITY.md
index ddaa915..a28e32f 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -33,8 +33,11 @@ These are the known CVEs reported for AntiSamy:
* AntiSamy CVE #3 - CVE-2021-35043: XSS via HTML attributes using : as replacement for : character before v1.6.4 - https://www.cvedetails.com/cve/CVE-2021-35043
* AntiSamy CVE #4 - CVE-2022-28367: AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content. https://www.cvedetails.com/cve/CVE-2022-28367. NOTE: This release only included a PARTIAL fix.
* AntiSamy CVE #5 - CVE-2022-29577: AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content. - https://www.cvedetails.com/cve/CVE-2022-29577. This is the complete fix to the previous CVE.
+* AntiSamy CVE #6 - CVE-2023-43643: AntiSamy before 1.7.4 subject to mXSS when preserving comments. - https://www.cvedetails.com/cve/CVE-2023-43643
CVEs in AntiSamy dependencies:
* AntiSamy prior to 1.6.6 used the old CyberNeko HTML library v1.9.22, which is subject to https://www.cvedetails.com/cve/CVE-2022-28366 and no longer maintained. AntiSamy 1.6.6 upgraded to an active fork of CyberNeko called HtmlUnit-Neko which fixed this CVE in v2.27 of that library. AntiSamy 1.6.6 upgraded to version 2.60.0 of HtmlUnit-Neko.
* AntiSamy 1.6.8 upgraded to HtmlUnit-Neko v2.61.0 because v2.60.0 is subject to https://www.cvedetails.com/cve/CVE-2022-29546
* AntiSamy 1.7.3 upgraded to HtmlUnit-Neko v3.1.0 because all versions prior to 3.0.0 are subject to https://www.cvedetails.com/cve/CVE-2023-26119
+* AntiSamy 1.7.4 upgraded to batik-css v1.17 because batik-css:1.16 is subject to https://www.cvedetails.com/cve/CVE-2022-44729
+
diff --git a/pom.xml b/pom.xml
index 7f46f4e..105e3a1 100644
--- a/pom.xml
+++ b/pom.xml
@@ -5,7 +5,7 @@
org.owasp.antisamy
antisamy
jar
- 1.7.4-SNAPSHOT
+ 1.7.4
@@ -52,7 +52,7 @@
2.0.0-M7
true
UTF-8
- 2023-04-21T10:00:00Z
+ 2023-10-06T21:08:34Z
1.8
1.12.0
2.0.9
@@ -73,7 +73,7 @@
org.htmlunit
neko-htmlunit
- 3.5.0
+ 3.6.0
org.apache.httpcomponents.client5
@@ -116,7 +116,7 @@
commons-io
commons-io
- 2.13.0
+ 2.14.0
org.slf4j