These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Nokogiri library versions before 1.19.3 contain a memory leak vulnerability in the XSLT Stylesheet transform method. This occurs when processing Ruby strings containing null bytes. An attacker can exploit this vulnerability by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes. Affect [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T16:17:28.460Z and has not been modified since then. The NVD entry is currently Analyzed. Nokogiri versions before 1.19.3 are vulnerable to regular expression denial of service attacks via CSS selector tokenizer, affecting string-literal and identifier tokenization. The vulnerability has a HIGH CV [truncated]
The Nokogiri library, prior to version 1.14.3, is vulnerable to NULL pointer dereferences during XML Schema processing due to the bundled libxml2 version 2.10.3. This issue, related to CVE-2023-28484, can be exploited by providing a crafted or malformed XML schema, potentially leading to a denial of service through a segfault. Developers and administrators should be aware of this vulnerability and take ne [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T16:16:44.380Z and has not been modified since then. Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheet [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T16:16:44.240Z and has not been modified since then. The vulnerability affects Nokogiri versions before 1.13.5 and involves an integer overflow in the packaged libxml2 buffer handling functions, allowing attackers to cause out-of-bounds memory writes by crafting multi-gigabyte XML files. This coul [truncated]
Nokogiri before 1.11.4, when using the CRuby implementation and the packaged libxml2 version 2.9.10, is vulnerable to multiple issues including memory leak (CVE-2019-20388), global buffer over-read (CVE-2020-24977), heap-based buffer overflow (CVE-2021-3517), and out-of-bounds read (CVE-2021-3518). These vulnerabilities were addressed in libxml2 version 2.9.12. The CVE record was published on 2026-08-25T1 [truncated]