PT-2026-81337 · Rubygems+1 · Nokogiri+1
CVE-2022-50999
·
Published
2022-05-18
·
Updated
2026-08-30
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nokogiri versions prior to 1.13.5
Description
An integer overflow exists in the packaged libxml2 buffer handling functions. This flaw allows attackers to cause out-of-bounds memory writes by crafting multi-gigabyte XML files. Such an action can trigger buffer overflows, leading to information disclosure, data modification, or denial of service.
Recommendations
Update Nokogiri to version 1.13.5 or later.
Exploit
Fix
Buffer Overflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokogiri
Libxml2