Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2022-51000: Nokogiri < 1.13.2 can be crashed by malicious XML or XSL

CVE-2022-51000 · published 1 month ago
Summary

Versions of the Nokogiri library earlier than 1.13.2 include older XML processing components that can be triggered by specially crafted XML or XSL files. An attacker could cause the application to stop working, reveal memory data, or even run code. Update Nokogiri to version 1.13.2 or later to fix the issue.

What to do
  • Update mike dalessio nokogiri to version 1.13.2.
  • Update sparklemotion nokogiri to version 1.13.2 or later.
Affected software
Ecosystem VendorProductAffected versions
rubygems mike dalessio nokogiri < 1.13.2
Fix: upgrade to 1.13.2
– sparklemotion nokogiri < 1.13.2
Ubuntu:Pro:14.04:LTS canonical ruby-nokogiri All versions
Original advisory text
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
Severity
9.9 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta