CVE-2026-79770
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Aug 25, 2026
Vendor
unknown
Description
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.