GHSA-qxcg-xjjg-66mjCriticalCVSS 9.8

Nokogiri vulnerable to libxslt protection mechanism bypass

Published
May 13, 2022
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

🎯 Affected products1

  • rubygems/nokogiri:< 1.10.3

🔗 References (26)