VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-79770

CVE-2026-79770: Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokeniz

Published Aug 25, 2026 CVSS 8.7

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

Affected AI Products

adversarial
Get the weekly digest. Every Monday: top AI security stories of the week. Free.