CVE-2021-47996
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-119
Restricción de operaciones inapropiada dentro de los límites del búfer de la memoria
Fecha de publicación:
25/08/2026
Última modificación:
25/08/2026
Descripción
*** Pendiente de traducción *** Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/sparklemotion/nokogiri/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5
- https://github.com/sparklemotion/nokogiri/commit/1098c30a040e72a4654968547f415be4e4c40fe7
- https://github.com/sparklemotion/nokogiri/commit/1358d157d0bd83be1dfe356a69213df9fac0b539
- https://github.com/sparklemotion/nokogiri/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2
- https://github.com/sparklemotion/nokogiri/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a
- https://github.com/sparklemotion/nokogiri/commit/8598060bacada41a0eb09d95c97744ff4e428f8e
- https://github.com/sparklemotion/nokogiri/commit/babe75030c7f64a37826bb3342317134568bef61
- https://github.com/sparklemotion/nokogiri/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64
- https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-via-libxml2



