CVE-2026-79771 UNKNOWN

CVE-2026-79771

Published: 2026-08-25

Description

Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…