cbcvebase.
CVE-2022-29181
published 2022-05-20

CVE-2022-29181: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers…

PriorityP346high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
3.08%
86.2th percentile
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

Affected

6 ranges
VendorProductVersion rangeFixed in
applemacos>= 13.0 < 13.113.1
applemacos_ventura
debianruby-nokogiri< ruby-nokogiri 1.13.7+dfsg-1 (bookworm)ruby-nokogiri 1.13.7+dfsg-1 (bookworm)
nokogirinokogiri< 1.13.61.13.6
nokogirinokogiri>= 0 < 1.13.61.13.6
sparklemotionnokogiri< 1.13.61.13.6

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv8.2HIGH
vendor_debian8.2LOW
vendor_redhat8.2HIGH
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.