Vulnerable Library - dotenv-rails-2.4.0.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Exploit Maturity |
EPSS |
Dependency |
Type |
Fixed in (dotenv-rails version) |
Remediation Possible** |
Reachability |
| CVE-2022-30123 |
Critical |
10.0 |
Not Defined |
1.801% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71407 |
Critical |
9.8 |
Not Defined |
0.418% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-58378 |
Critical |
9.8 |
Not Defined |
0.342% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-51000 |
Critical |
9.8 |
Not Defined |
0.441% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8165 |
Critical |
9.8 |
Not Defined |
45.732% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-11068 |
Critical |
9.8 |
Not Defined |
5.23% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| WS-2022-0089 |
High |
8.8 |
Not Defined |
|
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3518 |
High |
8.8 |
Not Defined |
3.653% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-30560 |
High |
8.8 |
Not Defined |
21.458% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-50999 |
High |
8.6 |
Not Defined |
0.301% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3517 |
High |
8.6 |
Not Defined |
8.28% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8161 |
High |
8.6 |
Not Defined |
3.359% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-29181 |
High |
8.2 |
Not Defined |
3.23% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23634 |
High |
8.0 |
Not Defined |
2.107% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71406 |
High |
7.8 |
Not Defined |
0.187% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| WS-2023-0224 |
High |
7.5 |
Not Defined |
|
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79770 |
High |
7.5 |
Not Defined |
0.278% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54904 |
High |
7.5 |
Not Defined |
0.673% |
concurrent-ruby-1.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34829 |
High |
7.5 |
Not Defined |
0.369% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34785 |
High |
7.5 |
Not Defined |
0.387% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33176 |
High |
7.5 |
Not Defined |
0.61% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-22860 |
High |
7.5 |
Not Defined |
0.665% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61919 |
High |
7.5 |
Not Defined |
0.605% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61772 |
High |
7.5 |
Not Defined |
0.868% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61771 |
High |
7.5 |
Not Defined |
0.523% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61770 |
High |
7.5 |
Not Defined |
0.868% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-59830 |
High |
7.5 |
Not Defined |
0.573% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-46727 |
High |
7.5 |
Not Defined |
1.157% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-27610 |
High |
7.5 |
Not Defined |
1.131% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-47887 |
High |
7.5 |
Not Defined |
1.041% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-41128 |
High |
7.5 |
Not Defined |
1.095% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-34459 |
High |
7.5 |
Not Defined |
2.298% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-54354 |
High |
7.5 |
Not Defined |
0.35% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-27530 |
High |
7.5 |
Not Defined |
1.83% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22796 |
High |
7.5 |
Not Defined |
1.712% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22795 |
High |
7.5 |
Not Defined |
2.278% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22792 |
High |
7.5 |
Not Defined |
1.695% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-50998 |
High |
7.5 |
Not Defined |
0.35% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44572 |
High |
7.5 |
Not Defined |
1.617% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44571 |
High |
7.5 |
Not Defined |
1.503% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44570 |
High |
7.5 |
Not Defined |
1.626% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-31163 |
High |
7.5 |
Not Defined |
2.23% |
tzinfo-1.2.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-30122 |
High |
7.5 |
Not Defined |
2.056% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-24836 |
High |
7.5 |
Not Defined |
3.549% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23517 |
High |
7.5 |
Not Defined |
1.454% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23516 |
High |
7.5 |
Not Defined |
1.095% |
loofah-2.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23514 |
High |
7.5 |
Not Defined |
1.686% |
loofah-2.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-47996 |
High |
7.5 |
Not Defined |
0.515% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-41098 |
High |
7.5 |
Not Defined |
1.447% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-22904 |
High |
7.5 |
Not Defined |
4.808% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-22885 |
High |
7.5 |
Not Defined |
4.195% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8184 |
High |
7.5 |
Not Defined |
2.938% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8164 |
High |
7.5 |
Not Defined |
4.198% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-7595 |
High |
7.5 |
Not Defined |
7.836% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5815 |
High |
7.5 |
Not Defined |
1.817% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5419 |
High |
7.5 |
Not Defined |
8.671% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5418 |
High |
7.5 |
High |
98.507% |
detected in multiple dependencies |
Transitive |
N/A* |
❌ |
|
| CVE-2019-18197 |
High |
7.5 |
Not Defined |
4.362% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-25032 |
High |
7.5 |
Not Defined |
51.733% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-16470 |
High |
7.5 |
Not Defined |
2.033% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-14404 |
High |
7.5 |
Not Defined |
3.65% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23633 |
High |
7.4 |
Not Defined |
2.226% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23519 |
High |
7.2 |
Not Defined |
0.988% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57235 |
Medium |
6.5 |
Not Defined |
0.426% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-25184 |
Medium |
6.5 |
Not Defined |
1.162% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8167 |
Medium |
6.5 |
Not Defined |
1.485% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8130 |
Medium |
6.4 |
Not Defined |
1.359% |
rake-12.3.1.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-16782 |
Medium |
6.3 |
Not Defined |
3.703% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57438 |
Medium |
6.2 |
Not Defined |
0.125% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-73648 |
Medium |
6.1 |
Not Defined |
0.396% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53989 |
Medium |
6.1 |
Not Defined |
0.463% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53988 |
Medium |
6.1 |
Not Defined |
0.435% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53987 |
Medium |
6.1 |
Not Defined |
0.435% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53986 |
Medium |
6.1 |
Not Defined |
0.462% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53985 |
Medium |
6.1 |
Not Defined |
0.581% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-32209 |
Medium |
6.1 |
Not Defined |
29.353% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-27777 |
Medium |
6.1 |
Not Defined |
1.639% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23520 |
Medium |
6.1 |
Not Defined |
1.11% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23518 |
Medium |
6.1 |
Not Defined |
0.867% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23515 |
Medium |
6.1 |
Not Defined |
0.792% |
loofah-2.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-8048 |
Medium |
6.1 |
Not Defined |
1.962% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-16471 |
Medium |
6.1 |
Not Defined |
1.89% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34830 |
Medium |
5.9 |
Not Defined |
0.209% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3537 |
Medium |
5.9 |
Not Defined |
3.503% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61780 |
Medium |
5.8 |
Not Defined |
0.434% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-26141 |
Medium |
5.8 |
Not Defined |
1.612% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79769 |
Medium |
5.5 |
Not Defined |
0.181% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33168 |
Medium |
5.4 |
Not Defined |
0.713% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-25500 |
Medium |
5.4 |
Not Defined |
0.224% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-15169 |
Medium |
5.4 |
Not Defined |
2.372% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-15587 |
Medium |
5.4 |
Not Defined |
1.561% |
loofah-2.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79772 |
Medium |
5.3 |
Not Defined |
0.262% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79771 |
Medium |
5.3 |
Not Defined |
0.304% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57437 |
Medium |
5.3 |
Not Defined |
0.402% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57436 |
Medium |
5.3 |
Not Defined |
0.402% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57435 |
Medium |
5.3 |
Not Defined |
0.46% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57434 |
Medium |
5.3 |
Not Defined |
0.46% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57236 |
Medium |
5.3 |
Not Defined |
0.341% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54905 |
Medium |
5.3 |
Not Defined |
0.153% |
concurrent-ruby-1.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34826 |
Medium |
5.3 |
Not Defined |
0.38% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34786 |
Medium |
5.3 |
Not Defined |
0.195% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34763 |
Medium |
5.3 |
Not Defined |
0.24% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34230 |
Medium |
5.3 |
Not Defined |
0.43% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33169 |
Medium |
5.3 |
Not Defined |
0.498% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-27111 |
Medium |
5.3 |
Not Defined |
0.729% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-26146 |
Medium |
5.3 |
Not Defined |
1.996% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-25126 |
Medium |
5.3 |
Not Defined |
35.376% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-28120 |
Medium |
5.3 |
Not Defined |
0.923% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-27539 |
Medium |
5.3 |
Not Defined |
1.081% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-13118 |
Medium |
5.3 |
Not Defined |
5.189% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-13117 |
Medium |
5.3 |
Not Defined |
6.457% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34831 |
Medium |
4.8 |
Not Defined |
0.147% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-73490 |
Medium |
4.7 |
Not Defined |
0.18% |
loofah-2.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33170 |
Medium |
4.3 |
Not Defined |
0.327% |
activesupport-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8166 |
Medium |
4.3 |
Not Defined |
1.673% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-32441 |
Medium |
4.2 |
Not Defined |
0.229% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54906 |
Medium |
4.0 |
Not Defined |
0.252% |
concurrent-ruby-1.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-28362 |
Medium |
4.0 |
Not Defined |
0.332% |
actionpack-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-5267 |
Medium |
4.0 |
Not Defined |
1.525% |
actionview-5.0.7.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-26961 |
Low |
3.7 |
Not Defined |
0.253% |
rack-2.0.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-6490 |
Low |
3.3 |
Proof of concept |
0.16% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71346 |
Low |
2.9 |
Not Defined |
0.18% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57234 |
Low |
2.6 |
Not Defined |
0.198% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-26247 |
Low |
2.6 |
Not Defined |
1.077% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-58377 |
Low |
0.0 |
Not Defined |
0.193% |
nokogiri-1.8.2.gem |
Transitive |
N/A* |
❌ |
|
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (10 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2022-30123
Vulnerable Library - rack-2.0.5.gem
Rack provides a minimal, modular and adaptable interface for developing
web applications in Ruby. By wrapping HTTP requests and responses in
the simplest way possible, it unifies and distills the API for web
servers, web frameworks, and software in between (the so-called
middleware) into a single method call.
Also see https://rack.github.io/.
Library home page: https://rubygems.org/gems/rack-2.0.5.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/rack-2.0.5.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- ❌ rack-2.0.5.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Publish Date: 2022-12-05
URL: CVE-2022-30123
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 1.801%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-wq4h-7r42-5hrr
Release Date: 2022-12-05
Fix Resolution: rack - 2.0.9.1,2.1.4.1,2.2.3.1
CVE-2025-71407
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Publish Date: 2026-08-25
URL: CVE-2025-71407
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.418%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.18.3,https://github.com/sparklemotion/nokogiri.git - v1.18.3
CVE-2024-58378
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Publish Date: 2026-08-25
URL: CVE-2024-58378
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.342%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-xc9x-jj77-9p9j
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.15.6,nokogiri - 1.16.2,https://github.com/sparklemotion/nokogiri.git - v1.15.6,https://github.com/sparklemotion/nokogiri.git - v1.16.2
CVE-2022-51000
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.
Publish Date: 2026-08-25
URL: CVE-2022-51000
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.441%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.2,https://github.com/sparklemotion/nokogiri.git - v1.13.2
CVE-2020-8165
Vulnerable Library - activesupport-5.0.7.gem
A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.
Library home page: https://rubygems.org/gems/activesupport-5.0.7.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activesupport-5.0.7.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- ❌ activesupport-5.0.7.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Publish Date: 2020-06-19
URL: CVE-2020-8165
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 45.732%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-2p68-f74v-9wc6
Release Date: 2020-06-19
Fix Resolution: activesupport - 5.2.4.3,activesupport - 6.0.3.1
CVE-2019-11068
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Publish Date: 2019-04-10
URL: CVE-2019-11068
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 5.23%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-qxcg-xjjg-66mj
Release Date: 2019-04-10
Fix Resolution: nokogiri - 1.10.3
WS-2022-0089
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Summary Nokogiri "v1.13.2" (https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.2) upgrades two of its packaged dependencies: - vendored libxml2 from v2.9.12 to "v2.9.13" (https://download.gnome.org/sources/libxml2/2.9/libxml2-2.9.13.news) - vendored libxslt from v1.1.34 to "v1.1.35" (https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.35.news) Those library versions address the following upstream CVEs: - libxslt: "CVE-2021-30560" (https://nvd.nist.gov/vuln/detail/CVE-2021-30560) (CVSS 8.8, High severity) - libxml2: "CVE-2022-23308" (https://nvd.nist.gov/vuln/detail/CVE-2022-23308) (Unspecified severity, see more information below) Those library versions also address numerous other issues including performance improvements, regression fixes, and bug fixes, as well as memory leaks and other use-after-free issues that were not assigned CVEs. Please note that this advisory only applies to the CRuby implementation of Nokogiri "< 1.13.2", and only if the packaged libraries are being used. If you've overridden defaults at installation time to use system libraries instead of packaged libraries, you should instead pay attention to your distro's "libxml2" and "libxslt" release announcements. Mitigation Upgrade to Nokogiri ">= 1.13.2". Users who are unable to upgrade Nokogiri may also choose a more complicated mitigation: compile and link an older version Nokogiri against external libraries libxml2 ">= 2.9.13" and libxslt ">= 1.1.35", which will also address these same CVEs. Impact libxslt "CVE-2021-30560" (https://nvd.nist.gov/vuln/detail/CVE-2021-30560) - CVSS3 score: 8.8 (High) - Fixed by https://gitlab.gnome.org/GNOME/libxslt/-/commit/50f9c9c All versions of libxslt prior to v1.1.35 are affected. Applications using untrusted XSL stylesheets to transform XML are vulnerable to a denial-of-service attack and should be upgraded immediately. libxml2 "CVE-2022-23308" (https://nvd.nist.gov/vuln/detail/CVE-2022-23308) - As of the time this security advisory was published, there is no officially published information available about this CVE's severity. The above NIST link does not yet have a published record, and the libxml2 maintainer has declined to provide a severity score. - Fixed by https://gitlab.gnome.org/GNOME/libxml2/-/commit/652dd12 - Further explanation is at https://mail.gnome.org/archives/xml/2022-February/msg00015.html The upstream commit and the explanation linked above indicate that an application may be vulnerable to a denial of service, memory disclosure, or code execution if it parses an untrusted document with parse options "DTDVALID" set to true, and "NOENT" set to false. An analysis of these parse options: - While "NOENT" is off by default for Document, DocumentFragment, Reader, and Schema parsing, it is on by default for XSLT (stylesheet) parsing in Nokogiri v1.12.0 and later. - "DTDVALID" is an option that Nokogiri does not set for any operations, and so this CVE applies only to applications setting this option explicitly. It seems reasonable to assume that any application explicitly setting the parse option "DTDVALID" when parsing untrusted documents is vulnerable and should be upgraded immediately.
Publish Date: 2026-05-28
URL: WS-2022-0089
Threat Assessment
Exploit Maturity: Not Defined
EPSS:
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-fq42-c5rg-92c2
Release Date: 2024-12-05
Fix Resolution: nokogiri - v1.13.2
CVE-2021-3518
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
Publish Date: 2021-05-18
URL: CVE-2021-3518
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 3.653%
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2021-3518
Release Date: 2021-05-18
Fix Resolution: libxml2 - 2.9.12
CVE-2021-30560
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Publish Date: 2021-08-03
URL: CVE-2021-30560
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 21.458%
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://security-tracker.debian.org/tracker/CVE-2021-30560
Release Date: 2021-08-03
Fix Resolution: v1.1.35,libxslt - 1.1.35
CVE-2022-50999
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
- dotenv-rails-2.4.0.gem (Root Library)
- railties-5.0.7.gem
- actionpack-5.0.7.gem
- actionview-5.0.7.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.8.2.gem (Vulnerable Library)
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
Publish Date: 2026-08-25
URL: CVE-2022-50999
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.301%
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.5,https://github.com/sparklemotion/nokogiri.git - v1.13.5
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - rack-2.0.5.gem
Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.
Also see https://rack.github.io/.
Library home page: https://rubygems.org/gems/rack-2.0.5.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/rack-2.0.5.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Publish Date: 2022-12-05
URL: CVE-2022-30123
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 1.801%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-wq4h-7r42-5hrr
Release Date: 2022-12-05
Fix Resolution: rack - 2.0.9.1,2.1.4.1,2.2.3.1
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Publish Date: 2026-08-25
URL: CVE-2025-71407
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.418%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.18.3,https://github.com/sparklemotion/nokogiri.git - v1.18.3
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Publish Date: 2026-08-25
URL: CVE-2024-58378
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.342%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-xc9x-jj77-9p9j
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.15.6,nokogiri - 1.16.2,https://github.com/sparklemotion/nokogiri.git - v1.15.6,https://github.com/sparklemotion/nokogiri.git - v1.16.2
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.
Publish Date: 2026-08-25
URL: CVE-2022-51000
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.441%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.2,https://github.com/sparklemotion/nokogiri.git - v1.13.2
Vulnerable Library - activesupport-5.0.7.gem
A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.
Library home page: https://rubygems.org/gems/activesupport-5.0.7.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activesupport-5.0.7.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Publish Date: 2020-06-19
URL: CVE-2020-8165
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 45.732%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-2p68-f74v-9wc6
Release Date: 2020-06-19
Fix Resolution: activesupport - 5.2.4.3,activesupport - 6.0.3.1
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Publish Date: 2019-04-10
URL: CVE-2019-11068
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 5.23%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-qxcg-xjjg-66mj
Release Date: 2019-04-10
Fix Resolution: nokogiri - 1.10.3
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Summary Nokogiri "v1.13.2" (https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.2) upgrades two of its packaged dependencies: - vendored libxml2 from v2.9.12 to "v2.9.13" (https://download.gnome.org/sources/libxml2/2.9/libxml2-2.9.13.news) - vendored libxslt from v1.1.34 to "v1.1.35" (https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.35.news) Those library versions address the following upstream CVEs: - libxslt: "CVE-2021-30560" (https://nvd.nist.gov/vuln/detail/CVE-2021-30560) (CVSS 8.8, High severity) - libxml2: "CVE-2022-23308" (https://nvd.nist.gov/vuln/detail/CVE-2022-23308) (Unspecified severity, see more information below) Those library versions also address numerous other issues including performance improvements, regression fixes, and bug fixes, as well as memory leaks and other use-after-free issues that were not assigned CVEs. Please note that this advisory only applies to the CRuby implementation of Nokogiri "< 1.13.2", and only if the packaged libraries are being used. If you've overridden defaults at installation time to use system libraries instead of packaged libraries, you should instead pay attention to your distro's "libxml2" and "libxslt" release announcements. Mitigation Upgrade to Nokogiri ">= 1.13.2". Users who are unable to upgrade Nokogiri may also choose a more complicated mitigation: compile and link an older version Nokogiri against external libraries libxml2 ">= 2.9.13" and libxslt ">= 1.1.35", which will also address these same CVEs. Impact libxslt "CVE-2021-30560" (https://nvd.nist.gov/vuln/detail/CVE-2021-30560) - CVSS3 score: 8.8 (High) - Fixed by https://gitlab.gnome.org/GNOME/libxslt/-/commit/50f9c9c All versions of libxslt prior to v1.1.35 are affected. Applications using untrusted XSL stylesheets to transform XML are vulnerable to a denial-of-service attack and should be upgraded immediately. libxml2 "CVE-2022-23308" (https://nvd.nist.gov/vuln/detail/CVE-2022-23308) - As of the time this security advisory was published, there is no officially published information available about this CVE's severity. The above NIST link does not yet have a published record, and the libxml2 maintainer has declined to provide a severity score. - Fixed by https://gitlab.gnome.org/GNOME/libxml2/-/commit/652dd12 - Further explanation is at https://mail.gnome.org/archives/xml/2022-February/msg00015.html The upstream commit and the explanation linked above indicate that an application may be vulnerable to a denial of service, memory disclosure, or code execution if it parses an untrusted document with parse options "DTDVALID" set to true, and "NOENT" set to false. An analysis of these parse options: - While "NOENT" is off by default for Document, DocumentFragment, Reader, and Schema parsing, it is on by default for XSLT (stylesheet) parsing in Nokogiri v1.12.0 and later. - "DTDVALID" is an option that Nokogiri does not set for any operations, and so this CVE applies only to applications setting this option explicitly. It seems reasonable to assume that any application explicitly setting the parse option "DTDVALID" when parsing untrusted documents is vulnerable and should be upgraded immediately.
Publish Date: 2026-05-28
URL: WS-2022-0089
Threat Assessment
Exploit Maturity: Not Defined
EPSS:
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-fq42-c5rg-92c2
Release Date: 2024-12-05
Fix Resolution: nokogiri - v1.13.2
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
Publish Date: 2021-05-18
URL: CVE-2021-3518
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 3.653%
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2021-3518
Release Date: 2021-05-18
Fix Resolution: libxml2 - 2.9.12
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Publish Date: 2021-08-03
URL: CVE-2021-30560
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 21.458%
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://security-tracker.debian.org/tracker/CVE-2021-30560
Release Date: 2021-08-03
Fix Resolution: v1.1.35,libxslt - 1.1.35
Vulnerable Library - nokogiri-1.8.2.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.8.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.8.2.gem
Dependency Hierarchy:
Found in HEAD commit: ab21a9f862ff3da3db0787ca394d129f490c3cfe
Found in base branch: main
Vulnerability Details
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
Publish Date: 2026-08-25
URL: CVE-2022-50999
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.301%
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.5,https://github.com/sparklemotion/nokogiri.git - v1.13.5