Количество 5
Количество 5
CVE-2026-79771
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.
CVE-2026-79771
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.
CVE-2026-79771
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.
CVE-2026-79771
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...
GHSA-v2fc-qm4h-8hqv
Nokogiri XSLT transform has a memory leak
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-79771 Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-79771 Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-79771 Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-79771 Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ... | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
GHSA-v2fc-qm4h-8hqv Nokogiri XSLT transform has a memory leak | CVSS3: 5.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу