PT-2022-16017 · Nokogiri+1 · Nokogiri+1

Davidwilemski

·

Published

2022-12-08

·

Updated

2026-03-13

·

CVE-2022-23476

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nokogiri versions 1.13.8 through 1.13.9
Description Nokogiri is an open source XML and HTML library for the Ruby programming language. It fails to check the return value from xmlTextReaderExpand in the method Nokogiri::XML::Reader#attribute hash. This can lead to a null pointer exception when invalid markup is being parsed. For applications using XML::Reader to parse untrusted inputs, this may potentially be a vector for a denial of service attack.
Recommendations Upgrade to Nokogiri >= 1.13.10. As a temporary workaround, consider searching code for calls to either XML::Reader#attributes or XML::Reader#attribute hash to determine if you are affected.

Exploit

Fix

DoS

NULL Pointer Dereference

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23476
GHSA-QV4Q-MR5R-QPRJ
OPENSUSE-SU-2024:13440-1
OPENSUSE-SU-2024:14174-1
OPENSUSE-SU-2025:14697-1
OPENSUSE-SU-2026:10356-1

Affected Products

Nokogiri
Red Os