OSV 1.4.0 · unreviewed · 修改于 2026-08-29 02:31
发布时间
2026-08-26 02:31
GitHub 审查时间
—
NVD 发布时间
2026-08-26 00:16
源文件
advisories/unreviewed/2026/08/GHSA-wf4q-gp79-7pv3/GHSA-wf4q-gp79-7pv3.json
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
该公告没有提供结构化的受影响软件包信息。