CVE-2022-50999 HIGH

CVE-2022-50999: Nokogiri before 1.13.5 Integer Overflow via libxml2

Vendor Sparklemotion
Product nokogiri
Weakness CWE-119
Published August 25, 2026
Last update August 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 28, 2026 Record updated