PT-2022-7455 · Rubygems+5 · Rails-Html-Sanitizer+5

Ooooooo_Q

·

Published

2022-12-13

·

Updated

2026-03-13

·

CVE-2022-23517

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions rails-html-sanitizer versions < 1.4.4
Description The issue is related to certain configurations of rails-html-sanitizer that use an inefficient regular expression. This inefficiency can lead to excessive backtracking when attempting to sanitize certain SVG attributes, resulting in a denial of service through CPU resource consumption. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations Upgrade to rails-html-sanitizer version 1.4.4 or later.

Exploit

Fix

RCE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1337
ALT-PU-2023-4269
ALT-PU-2024-7815
BDU:2024-06514
CVE-2022-23517
DLA-3566-1
DLA-3902-1
GHSA-5X79-W82F-GW8W
OPENSUSE-SU-2023_3714-1
OPENSUSE-SU-2024:12769-1
OPENSUSE-SU-2024:14175-1
OPENSUSE-SU-2025:15125-1
OPENSUSE-SU-2026:10361-1
RHSA-2023:2097
RLSA-2023:2097
SUSE-SU-2023:3534-1
SUSE-SU-2023:3714-1
SUSE-SU-2023_3714-1

Affected Products

Alt Linux
Astra Linux
Red Os
Rocky Linux
Suse
Rails-Html-Sanitizer