Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

Nokogiri Inefficient Regular Expression Complexity

GHSA-crjr-9rc5-ghw8 · CVE-2022-24836

Published · Modified

Description

Summary

Nokogiri < v1.13.4 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents.

Mitigation

Upgrade to Nokogiri >= 1.13.4.

Severity

The Nokogiri maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

CWE-1333 Inefficient Regular Expression Complexity

Credit

This vulnerability was reported by HackerOne user ooooooo_q (ななおく).

Ready to move

Start Securing

Free, no credit card | First findings in minutes