PT-2026-81337 · Rubygems+1 · Nokogiri+1

CVE-2022-50999

·

Published

2022-05-18

·

Updated

2026-08-30

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.13.5
Description An integer overflow exists in the packaged libxml2 buffer handling functions. This flaw allows attackers to cause out-of-bounds memory writes by crafting multi-gigabyte XML files. Such an action can trigger buffer overflows, leading to information disclosure, data modification, or denial of service.
Recommendations Update Nokogiri to version 1.13.5 or later.

Exploit

Fix

Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50999
GHSA-CGX6-HPWQ-FHV5

Affected Products

Nokogiri
Libxml2