MEDIUM 6.5 RubyGems

Uncontrolled resource consumption in nokogiri

GHSA-882p-jqgm-f45g · CVE-2017-18258

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes