OSV 1.4.0 · unreviewed · 修改于 2026-08-26 02:31
发布时间
2026-08-26 02:31
GitHub 审查时间
—
NVD 发布时间
2026-08-26 00:17
源文件
advisories/unreviewed/2026/08/GHSA-58vh-2xxg-v7j2/GHSA-58vh-2xxg-v7j2.json
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError.
该公告没有提供结构化的受影响软件包信息。