Nokogiri Gem Denial-of-Service Vulnerability: Critical CVEs
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- nokogiri (gem)
- Affected versions
- >= v1.1.34, <= v1.1.34 or >= v1.1.34-rc2, <= v1.1.34-rc2 or >= v1.1.33, <= v1.1.33 or >= v1.1.33-rc2, <= v1.1.33-rc2 or >= v1.1.33-rc1, <= v1.1.33-rc1 or >= v1.1.32, <= v1.1.32 or >= v1.1.32-rc2, <= v1.1.32-rc2 or >= v1.1.32-rc1, <= v1.1.32-rc1 or >= v1.1.31, <= v1.1.31 or >= v1.1.31-rc2, <= v1.1.31-rc2 or >= v1.1.31-rc1, <= v1.1.31-rc1 or >= v1.1.30, <= v1.1.30 or >= v1.1.30-rc2, <= v1.1.30-rc2 or >= v1.1.30-rc1, <= v1.1.30-rc1 or >= v1.1.29, <= v1.1.29 or >= v1.1.29-rc2, <= v1.1.29-rc2 or >= v1.1.29-rc1, <= v1.1.29-rc1 or >= CVE-2015-7995, <= CVE-2015-7995 or >= v1.1.28, <= v1.1.28 or >= v1.1.27, <= v1.1.27 or >= v1.1.27-rc1, <= v1.1.27-rc1 or >= v1.1.26, <= v1.1.26 or >= v1.1.25, <= v1.1.25 or >= 1.1.24, <= 1.1.24 or >= 1.1.23, <= 1.1.23 or >= LIBXSLT_1_1_22, <= LIBXSLT_1_1_22 or >= LIBXSLT_1_1_21, <= LIBXSLT_1_1_21 or >= LIBXSLT_1_1_18, <= LIBXSLT_1_1_18 or >= LIBXSLT_1_1_17, <= LIBXSLT_1_1_17 or >= LIBXSLT_1_1_16, <= LIBXSLT_1_1_16 or >= LIBXSLT_1_1_15, <= LIBXSLT_1_1_15 or >= LIBXSLT_1_1_14, <= LIBXSLT_1_1_14 or >= LIBXSLT_1_1_13, <= LIBXSLT_1_1_13 or >= LIBXSLT_1_1_12, <= LIBXSLT_1_1_12 or >= LIBXSLT_1_1_11, <= LIBXSLT_1_1_11 or >= LIBXSLT_1_1_10, <= LIBXSLT_1_1_10 or >= LIBXSLT_1_1_9, <= LIBXSLT_1_1_9 or >= LIBXSLT_1_1_8, <= LIBXSLT_1_1_8 or >= LIBXSLT_1_1_7, <= LIBXSLT_1_1_7 or >= LIBXSLT_1_1_6, <= LIBXSLT_1_1_6 or >= LIBXSLT_1_1_5, <= LIBXSLT_1_1_5 or >= LIBXSLT_1_1_4, <= LIBXSLT_1_1_4 or >= LIBXSLT_1_1_3, <= LIBXSLT_1_1_3 or >= LIBXSLT_1_1_2, <= LIBXSLT_1_1_2 or >= LIBXSLT_1_1_1, <= LIBXSLT_1_1_1 or >= LIBXSLT_1_1_0, <= LIBXSLT_1_1_0 or >= LIBXSLT_1_0_33, <= LIBXSLT_1_0_33 or >= LIBXSLT_1_0_32, <= LIBXSLT_1_0_32 or >= LIBXSLT_1_0_31, <= LIBXSLT_1_0_31 or >= LIBXSLT_1_0_30, <= LIBXSLT_1_0_30 or >= LIBXSLT_1_0_29, <= LIBXSLT_1_0_29 or >= LIBXSLT_1_0_28, <= LIBXSLT_1_0_28 or >= LIBXSLT_1_0_27, <= LIBXSLT_1_0_27 or >= LIBXSLT_1_0_26, <= LIBXSLT_1_0_26 or >= LIBXSLT_1_0_25, <= LIBXSLT_1_0_25 or >= LIBXSLT_1_0_24, <= LIBXSLT_1_0_24 or >= LIBXSLT_1_0_23, <= LIBXSLT_1_0_23 or >= LIBXSLT_1_0_22, <= LIBXSLT_1_0_22 or >= LIBXSLT_1_0_21, <= LIBXSLT_1_0_21 or >= LIBXSLT_1_0_20, <= LIBXSLT_1_0_20 or >= LIBXSLT_1_0_19, <= LIBXSLT_1_0_19 or >= LIBXSLT_1_0_18, <= LIBXSLT_1_0_18 or >= LIBXSLT_1_0_17, <= LIBXSLT_1_0_17 or >= LIBXSLT_1_0_16, <= LIBXSLT_1_0_16 or >= LIBXSLT_1_0_14, <= LIBXSLT_1_0_14 or >= LIBXSLT_1_0_13, <= LIBXSLT_1_0_13 or >= LIBXSLT_1_0_12, <= LIBXSLT_1_0_12 or >= LIBXSLT_1_0_11, <= LIBXSLT_1_0_11 or >= LIBXSLT_1_0_10, <= LIBXSLT_1_0_10 or >= LIBXSLT_1_0_9, <= LIBXSLT_1_0_9 or >= LIBXSLT_1_0_8, <= LIBXSLT_1_0_8 or >= LIBXSLT_1_0_7, <= LIBXSLT_1_0_7 or >= LIBXSLT_1_0_6, <= LIBXSLT_1_0_6 or >= LIBXSLT_1_0_5, <= LIBXSLT_1_0_5 or >= LIBXSLT_1_0_4, <= LIBXSLT_1_0_4 or >= LIBXSLT_1_0_3, <= LIBXSLT_1_0_3 or >= LIBXSLT_1_0_2, <= LIBXSLT_1_0_2 or >= LIBXSLT_1_0_0, <= LIBXSLT_1_0_0 or >= LIBXSLT_0_14_0, <= LIBXSLT_0_14_0 or >= LIBXSLT_0_13_0, <= LIBXSLT_0_13_0 or >= LIBXSLT_0_12_0, <= LIBXSLT_0_12_0 or >= LIBXSLT_0_11_0, <= LIBXSLT_0_11_0 or >= LIBXSLT_0_10_0, <= LIBXSLT_0_10_0 or >= LIBXSLT_0_9_0, <= LIBXSLT_0_9_0 or >= LIBXSLT_0_8_0, <= LIBXSLT_0_8_0 or >= LIBXSLT_0_7_0, <= LIBXSLT_0_7_0 or >= LIBXSLT_0_6_0, <= LIBXSLT_0_6_0 or >= LIXSLT_0_5_0, <= LIXSLT_0_5_0 or >= LIBXSLT_0_4_0, <= LIBXSLT_0_4_0 or >= LIBXSLT_0_3_0, <= LIBXSLT_0_3_0 or >= LIBXSLT_0_1_0, <= LIBXSLT_0_1_0 or >= LIBXSLT_0_0_0, <= LIBXSLT_0_0_0
- Patched version
- 1.13.2
Nokogiri gem versions before 1.13.2 are vulnerable to denial-of-service attacks due to issues in libxml2 and libxslt. Users of affected versions should upgrade immediately.
What happened
Nokogiri gem versions prior to 1.13.2 are vulnerable to denial-of-service attacks. This is due to the inclusion of vulnerable versions of libxml2 and libxslt, which are affected by CVE-2021-30560 and CVE-2022-23308 respectively. These vulnerabilities can be exploited when processing untrusted XML content, leading to potential denial of service, memory disclosure, or code execution.
The affected versions of Nokogiri ship with libxml2 2.9.12 and libxslt 1.1.34. Nokogiri 1.13.2 and above upgrade these libraries to patched versions, specifically libxml2 2.9.13 and libxslt 1.1.35, resolving the vulnerabilities.
What to do about it
- Upgrade Nokogiri to version 1.13.2 or later to mitigate the risk of denial-of-service attacks.
- Review your application's use of XML processing to ensure it does not rely on untrusted input.
- Monitor the NVD and Nokogiri project pages for further updates or advisories related to these vulnerabilities.
How 0Day would have caught this
nokogiri is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Nokogiri gem versions before 1.13.2, you are affected by this vulnerability.
What should I do right now?
Upgrade to Nokogiri 1.13.2 or later as soon as possible.
Are there any known exploits in the wild?
No, this vulnerability has not been exploited in the wild according to the provided data.