Memory Leak in XSLT Stylesheet Transform Method in Nokogiri by Sparklemotion
CVE-2026-79771

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79771?

Nokogiri, a popular Ruby library for parsing HTML and XML, has a vulnerability in versions prior to 1.19.3, specifically in the XSLT stylesheet transformation method. When processing Ruby strings that contain null bytes, this flaw enables attackers to manipulate input parameters with these null bytes. This can lead to significant memory leaks due to excessive heap allocations, thereby potentially causing denial of service in long-running processes. Users are advised to upgrade to version 1.19.3 or later to mitigate this risk.

Affected Version(s)

nokogiri 0 < 1.19.3

nokogiri 1.19.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Captainjack-kor
flavorjones
.