云虫漏洞库

CVE-2026-79772 - Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid. - 漏洞详情

漏洞编号:CVE-2026-79772

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-79772

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-252

发布/更新时间:2026-08-25 / 2026-08-28

漏洞描述

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.

相关链接

相关漏洞

« 返回首页