VDB
KO
HIGH 7.5

GHSA-x2fm-93ww-ggvx

Nokogiri gem, via libxml, is affected by DoS vulnerabilities

Details

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.8.1
Fix bundle update nokogiri

References