Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79772

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 5.3

Описание

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.

A flaw was found in Nokogiri. This vulnerability occurs because the canonicalize method fails to properly check the return value from an internal XML processing function, returning an empty string on failure instead of an error. A remote attacker could exploit this by providing specially crafted XML, leading to a bypass of signature validation in Security Assertion Markup Language (SAML) libraries that rely on Nokogiri, potentially allowing malicious data to be accepted as legitimate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Out of support scope
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/toolbox-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Out of support scope
Red Hat Satellite 6tfm-rubygem-amazing_printNot affected
Red Hat Satellite 6tfm-rubygem-graphqlFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-252
https://bugzilla.redhat.com/show_bug.cgi?id=2523567nokogiri: Nokogiri: Signature validation bypass via unchecked return value

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
23 дня назад

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.

CVSS3: 5.3
nvd
23 дня назад

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.

CVSS3: 5.3
debian
23 дня назад

Nokogiri versions before 1.19.1 fail to check the return value from xm ...

CVSS3: 5.3
github
7 месяцев назад

Nokogiri does not check the return value from xmlC14NExecute

5.3 Medium

CVSS3