CVE-2026-79772
- EPSS 0.26%
- Veröffentlicht 25.08.2026 15:16:04
- Zuletzt bearbeitet 01.09.2026 14:54:24
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstre...
CVE-2026-79771
- EPSS 0.3%
- Veröffentlicht 25.08.2026 15:16:03
- Zuletzt bearbeitet 01.09.2026 14:55:10
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters,...
CVE-2026-79770
- EPSS 0.28%
- Veröffentlicht 25.08.2026 15:16:03
- Zuletzt bearbeitet 01.09.2026 14:56:03
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css...
CVE-2026-57438
- EPSS 0.09%
- Veröffentlicht 25.06.2026 14:39:23
- Zuletzt bearbeitet 26.06.2026 04:11:23
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in place, freeing the include node along with its childr...
CVE-2026-57437
- EPSS 0.32%
- Veröffentlicht 25.06.2026 14:34:09
- Zuletzt bearbeitet 26.06.2026 16:47:23
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage collection. If an XPathContext outlived its document and the document w...
CVE-2026-57436
- EPSS 0.32%
- Veröffentlicht 25.06.2026 14:33:29
- Zuletzt bearbeitet 26.06.2026 16:47:15
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::XML::Node, allowing a DTD node to be set as the document root. The resu...
CVE-2026-57435
- EPSS 0.37%
- Veröffentlicht 25.06.2026 14:32:49
- Zuletzt bearbeitet 26.06.2026 13:32:43
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacing the value of an XML attribute. If Ruby code had a...
CVE-2026-57434
- EPSS 0.36%
- Veröffentlicht 25.06.2026 14:32:10
- Zuletzt bearbeitet 26.06.2026 13:32:33
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This...
CVE-2026-57235
- EPSS 0.34%
- Veröffentlicht 25.06.2026 14:31:10
- Zuletzt bearbeitet 26.06.2026 13:32:08
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index....
CVE-2026-57234
- EPSS 0.17%
- Veröffentlicht 25.06.2026 14:30:20
- Zuletzt bearbeitet 26.06.2026 19:03:15
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on the JRuby imp...