Loading HuntDB...

GHSA-59gp-qqm7-cw4j

GitHub Security Advisory

Nokogiri has vulnerable dependencies on libxml2 and libxslt

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected Packages

RubyGems nokogiri
Affected versions: 0 (fixed in 1.13.2)

Related CVEs

Key Information

GHSA ID
GHSA-59gp-qqm7-cw4j
Published
May 24, 2022 7:09 PM
Last Modified
June 23, 2023 9:37 PM
CVSS Score
7.5 /10
Primary Ecosystem
RubyGems
Primary Package
nokogiri
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 13, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.