Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-79770

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 25, 2026
Vendor unknown

Description

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

References