Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wf4q-gp79-7pv3

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.6

Описание

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

EPSS

Процентиль: 22%
0.00301
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.6
ubuntu
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

CVSS3: 7
redhat
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

CVSS3: 8.6
nvd
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

CVSS3: 8.6
debian
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerabil ...

EPSS

Процентиль: 22%
0.00301
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-119