Lucene search

K
osvGoogleOSV:GHSA-CRJR-9RC5-GHW8
HistoryApr 11, 2022 - 9:18 p.m.

Nokogiri Inefficient Regular Expression Complexity

2022-04-1121:18:06
Google
osv.dev
36

0.005 Low

EPSS

Percentile

77.6%

Summary

Nokogiri < v1.13.4 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents.

Mitigation

Upgrade to Nokogiri >= 1.13.4.

Severity

The Nokogiri maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

CWE-1333 Inefficient Regular Expression Complexity

Credit

This vulnerability was reported by HackerOne user ooooooo_q (ăȘăȘおく).

References