[Git][security-tracker-team/security-tracker][master] bogus CVE assignments for nokogiri by vulncheck

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 28 10:35:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
70a452ac by Moritz Muehlenhoff at 2026-08-28T10:14:35+02:00
bogus CVE assignments for nokogiri by vulncheck

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4896,25 +4896,25 @@ CVE-2026-12878 (In affected versions of the Codefresh platform an authenticated
 CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) d ...)
 	TODO: check
 CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability  ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior  ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxslt)
 CVE-2025-71346 (Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (befor ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2024-58378 (Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2024-58377 (Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affect ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2023-54354 (Nokogiri before 1.14.3 (CRuby implementation only, when using the pack ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2022-51000 (Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships ve ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2022-50999 (Nokogiri versions before 1.13.5 contain an integer overflow vulnerabil ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2022-50998 (Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/v ...)
-	TODO: check
+	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2026-63676
 	- libyaml-perl 1.321-1
 	[trixie] - libyaml-perl <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70a452aca93614e0dfe484157bc2b7b0964160e4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70a452aca93614e0dfe484157bc2b7b0964160e4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/97d5e8c8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list