Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50998

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.)

A flaw was found in Nokogiri, a Ruby gem for parsing XML and HTML documents. This vulnerability arises from issues within its bundled libxml2 library, specifically involving data corruption from entity reference cycles and integer overflows when processing large XML files. A remote attacker could exploit these flaws by providing specially crafted XML input, potentially leading to denial of service or memory corruption within the application.

Отчет

This vulnerability is rated as Important because it can lead to denial of service or memory corruption when processing specially crafted XML input. Red Hat products utilizing rubygem-nokogiri are affected, making systems susceptible if they handle untrusted XML data. The flaw stems from underlying issues in libxml2 bundled with Nokogiri, which could be triggered without complex attack vectors.

Меры по смягчению последствий

To mitigate this Important vulnerability, applications processing untrusted XML input via Nokogiri should implement strict input validation and sanitization. Restrict the sources of XML input to trusted origins only. Where possible, isolate or sandbox applications that process external XML to limit the potential blast radius of a successful exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/toolbox-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Not affected
Red Hat Hardened Imageslibxml2Not affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat Satellite 6rubygem-nokogiriNot affected
Red Hat Satellite 6tfm-rubygem-amazing_printNot affected
Red Hat Satellite 6tfm-rubygem-graphqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2523558nokogiri: libxml2: Nokogiri: Denial of Service and Memory Corruption via Crafted XML Input

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
20 дней назад

Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.)

nvd
20 дней назад

Rejected reason: This CVE ID has been rejected as a duplicate.

CVSS3: 7.5
github
20 дней назад

Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.)

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3