🚨 CVE-2022-50999
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
🎖@cveNotify
GitHub
[CVE-2022-29824] Fix integer overflows in xmlBuf and xmlBuffer · GNOME/libxml2@2554a24
In several places, the code handling string buffers didn't check for
integer overflow or used wrong types for buffer sizes. This could
result in out-of-bounds writes or other memory errors ...
September 1, 2026 6