Nokogiri

Nokogiri

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 02.12.2024 22:15:11
  • Last modified 15.08.2025 19:41:49

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x ...

  • EPSS 0.19%
  • Published 08.12.2022 04:15:09
  • Last modified 21.11.2024 06:48:38

Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null ...

Exploit
  • EPSS 5.34%
  • Published 20.05.2022 19:15:08
  • Last modified 27.05.2025 15:15:24

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault)...

  • EPSS 1.5%
  • Published 11.04.2022 22:15:07
  • Last modified 21.11.2024 06:51:12

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...

Exploit
  • EPSS 0.09%
  • Published 25.03.2022 09:15:08
  • Last modified 21.08.2025 20:37:11

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

  • EPSS 0.74%
  • Published 27.09.2021 20:15:07
  • Last modified 21.11.2024 06:25:27

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who parse untrust...

  • EPSS 1.17%
  • Published 30.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:38

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing ...

Exploit
  • EPSS 0.32%
  • Published 19.02.2020 15:15:11
  • Last modified 21.11.2024 01:46:40

Nokogiri before 1.5.4 is vulnerable to XXE attacks

Exploit
  • EPSS 2.52%
  • Published 05.11.2019 15:15:11
  • Last modified 21.11.2024 01:59:16

Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

Exploit
  • EPSS 2.05%
  • Published 05.11.2019 15:15:11
  • Last modified 21.11.2024 01:59:16

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits