CVEs we hold for Sparklemotion
Records whose assigning authority named Sparklemotion as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-79769Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_argssparklemotion nokogiri
CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimesparklemotion nokogiri
CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typesparklemotion nokogiri
CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`sparklemotion nokogiri
CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classessparklemotion nokogiri
CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionsparklemotion nokogiri
CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`sparklemotion nokogiri
CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247sparklemotion nokogiri
CVE-2026-54620sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbackssparklemotion sqlite3-ruby
CVE-2026-54619sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Aritysparklemotion sqlite3-ruby
CVE-2025-6494sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflowsparklemotion nokogiri
CVE-2025-6490sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflowsparklemotion nokogiri
CVE-2022-51000Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxsltsparklemotion nokogiri
CVE-2022-24839Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork)sparklemotion nekohtml
CVE-2021-41098Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRubysparklemotion nokogiri
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.