CVE-2026-79770High· 7.5▾ TwilightNokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.3%
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.
nokogiri < 1.19.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-25032High· 7.5zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
GHSA-5v8h-3h3q-446pLowNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
GHSA-8678-w3jw-xfc2Low· 2.6Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
GHSA-9cv2-cfxc-v4v2LowNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
GHSA-wjv4-x9w8-wm3hLowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type