CVE-2022-50999 Nokogiri versions before 1.13.5 contain an integer… — CVE Notify — TG.ME

🚨 CVE-2022-50999
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

🎖@cveNotify
GitHub
[CVE-2022-29824] Fix integer overflows in xmlBuf and xmlBuffer · GNOME/libxml2@2554a24
In several places, the code handling string buffers didn't check for integer overflow or used wrong types for buffer sizes. This could result in out-of-bounds writes or other memory errors ...
September 1, 2026 6