A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | |
Title | sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow | |
Weaknesses | CWE-119 CWE-122 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-22T19:00:11.556Z
Updated: 2025-06-22T19:00:11.556Z
Reserved: 2025-06-21T15:08:00.753Z
Link: CVE-2025-6490

No data.

Status : Received
Published: 2025-06-22T19:15:20.790
Modified: 2025-06-22T19:15:20.790
Link: CVE-2025-6490

No data.