CVE-2026-79771

Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2026-08-25 16:17

Updated : 2026-09-01 14:55


NVD link : CVE-2026-79771

Mitre link : CVE-2026-79771

CVE.ORG link : CVE-2026-79771


JSON object : View

Products Affected

nokogiri

  • nokogiri
CWE
CWE-401

Missing Release of Memory after Effective Lifetime