CVE-2022-50999
Severity CVSS v4.0:
HIGH
Type:
CWE-119
Buffer Errors
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
8.60
Severity 3.x
HIGH



