← Back to overview

Nokogiri versions prior to 1.13.5 contain an integer overflow vulnerability in the packaged libxml2 buffer handling functions. The flaw enables attackers to cause out-of-bounds memory writes by crafting multi-gigabyte XML files that trigger buffer overflows. Successful exploitation can lead to information disclosure, unauthorized data modification, or denial of service conditions. The vulnerability originates in the underlying libxml2 library bundled with Nokogiri, a widely used Ruby XML/HTML parsing library. A patch was issued in Nokogiri 1.13.5, and users are advised to upgrade immediately. The issue is tracked under CVE-2022-50999 and has been assigned a High criticality rating. Multiple references including a GitHub commit, a security advisory, and a VulnCheck entry document the vulnerability and its remediation.

Affected products

  • Nokogiri
  • libxml2

Related CVE's

  • CVE-2022-50999

Categories

  • Supply Chain & Dependencies
  • Web Technologies