Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-79770

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:*
Версия до 1.19.3 (исключая)

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

CVSS3: 7.5
redhat
23 дня назад

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

CVSS3: 7.5
debian
23 дня назад

Nokogiri versions before 1.19.3 contain regular expression denial of s ...

CVSS3: 7.5
github
4 месяца назад

Nokogiri CSS selector tokenizer has regular expression backtracking

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333