CVE-2022-50999
HIGH
NVD
CVSS Score
8.6
Severity
HIGH
Published
Aug 25, 2026
Vendor
unknown
Description
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.