{"id":"GHSA-gx8x-g87m-h5q6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gx8x-g87m-h5q6","summary":"Denial of Service (DoS) in Nokogiri on JRuby","details":"## Summary\n\nNokogiri `v1.13.4` updates the vendored `org.cyberneko.html` library to `1.9.22.noko2` which addresses [CVE-2022-24839](https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv). That CVE is rated 7.5 (High Severity).\n\nSee [GHSA-9849-p7jc-9rmv](https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv) for more information.\n\nPlease note that this advisory only applies to the **JRuby** implementation of Nokogiri `< 1.13.4`.\n\n\n## Mitigation\n\nUpgrade to Nokogiri `>= 1.13.4`.\n\n\n## Impact\n\n### [CVE-2022-24839](https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv) in nekohtml\n\n- **Severity**: High 7.5\n- **Type**: [CWE-400](https://cwe.mitre.org/data/definitions/400.html) Uncontrolled Resource Consumption\n- **Description**: The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup.\n- **See also**: [GHSA-9849-p7jc-9rmv](https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv)\n","published":"2022-04-11T21:38:11Z","modified":"2024-12-05T05:37:10.384695Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"nokogiri","fixedVersion":"1.13.4"}],"fix":{"url":"https://github.com/sparklemotion/nekohtml/commit/a800fce3b079def130ed42a408ff1d09f89e773d","label":"sparklemotion/nekohtml@a800fce"},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv"},{"type":"WEB","url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-gx8x-g87m-h5q6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24839"},{"type":"WEB","url":"https://github.com/sparklemotion/nekohtml/commit/a800fce3b079def130ed42a408ff1d09f89e773d"},{"type":"PACKAGE","url":"https://github.com/sparklemotion/nokogiri"},{"type":"WEB","url":"https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.4"},{"type":"WEB","url":"https://groups.google.com/g/ruby-security-ann/c/vX7qSjsvWis/m/TJWN4oOKBwAJ?utm_medium=email&utm_source=footer"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:37:10.384695Z"}}