CVE-2022-23516: Uncontrolled Recursion in Loofah

Published Dec 13, 2022
·
Updated

Summary

Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption.

Mitigation

Upgrade to Loofah >= 2.19.1.

Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

Severity

The Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

- CWE - CWE-674: Uncontrolled Recursion (4.9)

Other sources

An uncontrolled recursion vulnerability was found in rubygem loofah. While sanitizing certain sections, loofah is susceptible to stack exhaustion, which can result in a denial of service through CPU resource consumption.

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

Affected Software

4 affected componentsFixes available
rubygems/loofah>=2.2.0<2.19.1
2.19.1
redhat/rubygem-loofah<0:2.19.1-1.el8
0:2.19.1-1.el8
redhat/rubygem-loofah<2.19.1
2.19.1
Loofah Project Loofah Ruby>=2.2.0<2.19.1

Event History

Dec 13, 2022
CVE Published
12:00 AM
Advisory Published
05:40 PM
Dec 14, 2022
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-23516?

CVE-2022-23516 is classified as a denial of service vulnerability due to potential stack exhaustion.

2

How do I fix CVE-2022-23516?

To fix CVE-2022-23516, upgrade to Loofah version 2.19.1 or later.

3

What versions of Loofah are affected by CVE-2022-23516?

Loofah versions between 2.2.0 and 2.19.0 are affected by CVE-2022-23516.

4

What can happen if I do not address CVE-2022-23516?

If you do not address CVE-2022-23516, your application may become susceptible to denial of service attacks due to high CPU usage.

5

Is CVE-2022-23516 related to any specific software?

CVE-2022-23516 specifically affects the Loofah Ruby gem.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203