Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#atcss, and Searchable#search to cause exponential regex backtracking and denial of service.
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
Rejected reason: This CVE ID has been rejected as a duplicate.
Two type confusion issues while processing malicious data can be used to leak the contents of memory or cause a denial-of-service.
Two type confusion issues while processing malicious data can be used to leak the contents of memory or cause a denial-of-service.