GHSA-wf4q-gp79-7pv3HighCVSS 8.6

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2...

Published
August 25, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

🔗 References (6)