sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow

CVE Details

Basic Information

Title sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
Type cve
Published 2025-06-22T19:00:11.556Z
Last Seen

Product Information

Vendor sparklemotion
Product nokogiri
Version 1.18.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A heap-based buffer overflow vulnerability in the gumbo-parser component of sparklemotion nokogiri could allow local attackers to execute arbitrary code or cause a denial of service. This issue affects versions up to 1.18.7.
AI Severity Medium
Vendor sparklemotion
Product nokogiri
Affected Version 1.18.0, 1.18.1, 1.18.2, 1.18.3, 1.18.4, 1.18.5, 1.18.6, 1.18.7

Affected Products

  • sparklemotion nokogiri 1.18.0
  • sparklemotion nokogiri 1.18.1
  • sparklemotion nokogiri 1.18.2
  • sparklemotion nokogiri 1.18.3
  • sparklemotion nokogiri 1.18.4
  • sparklemotion nokogiri 1.18.5
  • sparklemotion nokogiri 1.18.6
  • sparklemotion nokogiri 1.18.7

Additional Information

CVE List
CWE List CWE-122, CWE-119
Bulletin Family

Description

A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.