{"id":"CVE-2022-29181","aliases":["GHSA-xh29-r2w5-wx8m"],"url":"https://o3.security/vulnerability/CVE-2022-29181","summary":"Improper Handling of Unexpected Data Type in Nokogiri","details":"Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.","published":"2022-05-20T00:00:00Z","modified":"2026-08-12T13:00:55.214422Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"nokogiri","fixedVersion":"1.13.6"}],"fix":{"url":"https://github.com/sparklemotion/nokogiri/commit/83cc451c3f29df397caa890afc3b714eae6ab8f7","label":"sparklemotion/nokogiri@83cc451"},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.6"},{"type":"WEB","url":"https://support.apple.com/kb/HT213532"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29181.json"},{"type":"ADVISORY","url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xh29-r2w5-wx8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29181"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-29"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2022-031_GHSL-2022-032_Nokogiri"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2022-031_GHSL-2022-032_Nokogiri/"},{"type":"FIX","url":"https://github.com/sparklemotion/nokogiri/commit/83cc451c3f29df397caa890afc3b714eae6ab8f7"},{"type":"FIX","url":"https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2022/Dec/23"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:00:55.214422Z"}}