top of page
perceptive_background_267k.jpg

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifi…

Published:

25 August 2026 at 00:00:00

Alert date:

25 August 2026 at 19:07:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

Nokogiri versions prior to 1.19.3 are vulnerable to Regular Expression Denial of Service (ReDoS) in the CSS selector tokenizer. The vulnerability affects string-literal and identifier tokenization within the library. Attackers can exploit this by injecting adversarial CSS selectors into methods such as Node#css, Node#at_css, and Searchable#search. This causes exponential regex backtracking, leading to denial of service conditions. The vulnerability is tracked as CVE-2026-79770 and has been patched in Nokogiri 1.19.3. Users of affected versions should upgrade immediately to mitigate the risk. The issue is documented across NVD, GitHub Security Advisories, and VulnCheck.

Technical details

Mitigation steps:

Affected products:

Nokogiri < 1.19.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page