Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-47996

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.

A flaw was found in Nokogiri, specifically within its bundled libxml2 library. A remote attacker could exploit multiple vulnerabilities, including memory leaks, buffer over-reads, heap-based buffer overflows, and out-of-bounds reads, by processing specially crafted XML documents. This could lead to memory corruption, information disclosure, or a denial of service.

Отчет

Important: Red Hat products utilizing Nokogiri are affected by multiple vulnerabilities in its bundled libxml2 library, which can lead to denial of service, information disclosure, or memory corruption when processing specially crafted XML documents. While Nokogiri's default parse options prevent exponential entity expansion attacks, other flaws remain.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/toolbox-rhel9Affected
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Not affected
Red Hat Satellite 6rubygem-nokogiriNot affected
Red Hat Satellite 6tfm-rubygem-amazing_printNot affected
Red Hat Satellite 6tfm-rubygem-graphqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2523549nokogiri: libxml2: Nokogiri: Memory Corruption via Crafted XML Documents

EPSS

Процентиль: 42%
0.00515
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
14 дней назад

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.

CVSS3: 7.5
nvd
14 дней назад

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.

CVSS3: 7.5
debian
14 дней назад

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/v ...

CVSS3: 7.5
github
14 дней назад

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.

EPSS

Процентиль: 42%
0.00515
Низкий

7.5 High

CVSS3