{"id":"CVE-2017-16932","aliases":["GHSA-x2fm-93ww-ggvx"],"url":"https://o3.security/vulnerability/CVE-2017-16932","summary":"Nokogiri gem, via libxml, is affected by DoS vulnerabilities","details":"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.","published":"2017-11-23T21:29:00.437Z","modified":"2026-08-07T14:48:56.964492Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.05928,"percentile":0.92683,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"nokogiri","fixedVersion":"1.8.1"}],"fix":{"url":"https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961","label":"GNOME/libxml2@899a5d9"},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html"},{"type":"WEB","url":"https://usn.ubuntu.com/3739-1/"},{"type":"ADVISORY","url":"http://xmlsoft.org/news.html"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=759579"},{"type":"FIX","url":"https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/libxml2/-/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961"},{"type":"ARTICLE","url":"https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:56.964492Z"}}