GHSA-cf46-6xxh-pc75HighCVSS 7.5

libxslt Type Confusion vulnerability that affects Nokogiri

Published
May 24, 2022
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.

🎯 Affected products1

  • rubygems/nokogiri:< 1.10.5

🔗 References (50)