


Perceptive Security
SOC/SIEM Consultancy

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifi…
Published:
25 August 2026 at 00:00:00
Alert date:
25 August 2026 at 19:07:30
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
Nokogiri versions prior to 1.19.3 are vulnerable to Regular Expression Denial of Service (ReDoS) in the CSS selector tokenizer. The vulnerability affects string-literal and identifier tokenization within the library. Attackers can exploit this by injecting adversarial CSS selectors into methods such as Node#css, Node#at_css, and Searchable#search. This causes exponential regex backtracking, leading to denial of service conditions. The vulnerability is tracked as CVE-2026-79770 and has been patched in Nokogiri 1.19.3. Users of affected versions should upgrade immediately to mitigate the risk. The issue is documented across NVD, GitHub Security Advisories, and VulnCheck.
Technical details
Mitigation steps:
Affected products:
Nokogiri < 1.19.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-79770
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx
https://www.vulncheck.com/advisories/nokogiri-before-redos-via-css-selector-tokenizer
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
