CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2022-51000

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-25
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.

⚡ Watch CVE-2022-51000

Get an email if CVE-2022-51000 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2022-51000

CVE.org record

Embed the live status

CVE-2022-51000 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2022-51000 status](https://www.csirts.com/badge/CVE-2022-51000)](https://www.csirts.com/cve/CVE-2022-51000)