Vulnerability Description
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokogiri | Nokogiri | < 1.19.3 |
Related Weaknesses (CWE)
References
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqVendor Advisory
- https://www.vulncheck.com/advisories/nokogiri-before-memory-leak-via-xslt-transfThird Party Advisory
FAQ
What is CVE-2026-79771?
CVE-2026-79771 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-control...
How severe is CVE-2026-79771?
CVE-2026-79771 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79771?
Check the references section above for vendor advisories and patch information. Affected products include: Nokogiri Nokogiri.