Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2022-51000: Nokogiri < 1.13.2 can be crashed by malicious XML or XSL
CVE-2022-51000 · published 1 month ago
Summary
Versions of the Nokogiri library earlier than 1.13.2 include older XML processing components that can be triggered by specially crafted XML or XSL files. An attacker could cause the application to stop working, reveal memory data, or even run code. Update Nokogiri to version 1.13.2 or later to fix the issue.
What to do
- Update mike dalessio nokogiri to version 1.13.2.
- Update sparklemotion nokogiri to version 1.13.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| rubygems | mike dalessio | nokogiri |
< 1.13.2 Fix: upgrade to 1.13.2
|
| – | sparklemotion | nokogiri | < 1.13.2 |
| Ubuntu:Pro:14.04:LTS | canonical | ruby-nokogiri | All versions |
Original advisory text
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
References
- https://github.com/advisories/GHSA-fq42-c5rg-92c2
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/51xxx/CVE-2022-51000... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-51000 Vendor Advisory
- https://github.com/GNOME/libxml2/commit/652dd12 Third Party Advisory
- https://github.com/GNOME/libxslt/commit/50f9c9c Third Party Advisory
- https://github.com/sparklemotion/nokogiri/commit/50f9c9c Patch
- https://github.com/sparklemotion/nokogiri/commit/652dd12 Patch
- https://ubuntu.com/security/CVE-2022-51000 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-51000 Third Party Advisory
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-fq42-c5rg-92c... Third Party Advisory
- https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-vi... Third Party Advisory
Severity
9.9
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen6 Mar 2026
Sources
CVE-2022-51000 · NVD
CVE-2022-51000 · MITRE
GHSA-fq42-c5rg-92c2 · GHSA
CVE-2022-51000 · OSV
UBUNTU-CVE-2022-51000 · OSV
Track software like this
Free during beta