VDB
KO
MEDIUM

GHSA-q7wx-62r7-j2x7

Nokogiri vulnerable to libxml XML Entity Expansion

Details

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 1.6.6.0 Fixed in: 1.6.6.4
Fix bundle update nokogiri

References