GHSA-4hm9-844j-jmxpMediumCVSS 5.3

Uninitialized read in Nokogiri gem

Published
May 24, 2022
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

🎯 Affected products1

  • rubygems/nokogiri:< 1.10.5

🔗 References (20)