Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.)
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sparklemotion
Sparklemotion nokogiri |
|
| Vendors & Products |
Sparklemotion
Sparklemotion nokogiri |
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.) | |
| Title | Nokogiri before 1.13.9 Multiple Vulnerabilities via libxml2 | |
| First Time appeared |
Nokogiri
Nokogiri nokogiri |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokogiri
Nokogiri nokogiri |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T15:15:53.830Z
Reserved: 2026-08-25T14:31:37.341Z
Link: CVE-2022-50998
No data.
Status : Received
Published: 2026-08-25T16:16:44.073
Modified: 2026-08-25T16:16:44.073
Link: CVE-2022-50998
No data.
OpenCVE Enrichment
Updated: 2026-08-25T20:00:06Z
Weaknesses