vciy

CVEs we hold for Sparklemotion

Records whose assigning authority named Sparklemotion as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-79772Nokogiri before 1.19.1 Unchecked Return Value canonicalizesparklemotion nokogiri
CVE-2026-79771Nokogiri before 1.19.3 Memory Leak via XSLT Transformsparklemotion nokogiri
CVE-2026-79770Nokogiri before 1.19.3 ReDoS via CSS selector tokenizersparklemotion nokogiri
CVE-2026-79769Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_argssparklemotion nokogiri
CVE-2026-57438Nokogiri: Possible Use-After-Free in XInclude Processingsparklemotion nokogiri
CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimesparklemotion nokogiri
CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typesparklemotion nokogiri
CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`sparklemotion nokogiri
CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classessparklemotion nokogiri
CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionsparklemotion nokogiri
CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`sparklemotion nokogiri
CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247sparklemotion nokogiri
CVE-2026-54620sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbackssparklemotion sqlite3-ruby
CVE-2026-54619sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Aritysparklemotion sqlite3-ruby
CVE-2025-6494sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflowsparklemotion nokogiri
CVE-2025-6490sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflowsparklemotion nokogiri
CVE-2023-54354Nokogiri before 1.14.3 Null Pointer Dereference via libxml2sparklemotion nokogiri
CVE-2022-51000Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxsltsparklemotion nokogiri
CVE-2022-50999Nokogiri before 1.13.5 Integer Overflow via libxml2sparklemotion nokogiri
CVE-2022-50998Nokogiri before 1.13.9 Multiple Vulnerabilities via libxml2sparklemotion nokogiri
CVE-2022-31033Authorization header leak in rubygem Mechanizesparklemotion mechanize
CVE-2022-29181Improper Handling of Unexpected Data Type in Nokogirisparklemotion nokogiri
CVE-2022-24839Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork)sparklemotion nekohtml
CVE-2022-24836Inefficient Regular Expression Complexity in Nokogirisparklemotion nokogiri
CVE-2022-23476Unchecked return value from xmlTextReaderExpand in Nokogirisparklemotion nokogiri
CVE-2021-47996Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2sparklemotion nokogiri
CVE-2021-41098Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRubysparklemotion nokogiri
CVE-2021-21289Command Injection Vulnerability in Mechanizesparklemotion mechanize
CVE-2020-26247XXE in Nokogirisparklemotion nokogiri

29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.