Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57434

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 2.9

Описание

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.

A flaw was found in Nokogiri, an open source XML and HTML library for the Ruby programming language. A remote attacker could exploit this vulnerability by calling specific methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This could lead to a NULL pointer dereference, causing the process to crash and resulting in a Denial of Service (DoS).

Отчет

A flaw was found in Nokogiri, an open source XML and HTML library for Ruby. Calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node triggers a NULL pointer dereference, crashing the process. An attacker who can control the construction of Nokogiri node objects could exploit this to cause a Denial of Service. The vulnerability is fixed in Nokogiri 1.19.4.

Меры по смягчению последствий

There is no mitigation for this flaw other than updating to Nokogiri version 1.19.4 or later. As a workaround, ensure that untrusted input cannot trigger the construction of uninitialized native wrapper classes inheriting from Nokogiri::XML::Node.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/backendFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/zyncFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/backendFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/zyncFix deferred
Red Hat 3scale API Management Platform 23scale-amp26/toolboxFix deferred
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2492935nokogiri: rubygem-nokogiri: Nokogiri: Denial of Service via NULL pointer dereference

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.

CVSS3: 7.5
nvd
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.

CVSS3: 7.5
msrc
около 1 месяца назад

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

CVSS3: 7.5
debian
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programmi ...

2.9 Low

CVSS3