intertwingly.net/blog/2026/09...
intertwingly.net/blog/2026/09...
declared — puma, bcrypt, nio4r, json, openssl
not — sqlite3, nokogiri
sqlite3 is the hot one (a few hundred rows/request). --cexts-lock=false: 432 → 1,078 req/s at 5 threads
declared — puma, bcrypt, nio4r, json, openssl
not — sqlite3, nokogiri
sqlite3 is the hot one (a few hundred rows/request). --cexts-lock=false: 432 → 1,078 req/s at 5 threads
…養老渓谷と鋸山、どっちも複合名詞なのに、なんでYoro Valleyは分ち書きでNokogiriyamaは単一名詞として書かれてるんだろ。
Nokogiri Mountainじゃないかな、揃えるとしたら。
…養老渓谷と鋸山、どっちも複合名詞なのに、なんでYoro Valleyは分ち書きでNokogiriyamaは単一名詞として書かれてるんだろ。
Nokogiri Mountainじゃないかな、揃えるとしたら。
The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML definitions from untrusted…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML definitions from untrusted…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
Versions of the Nokogiri library earlier than 1.16.5 ship with an older copy of the libxml2 XML processor that contains a known weakness. The flaw is in a command‑line tool…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
Versions of the Nokogiri library earlier than 1.16.5 ship with an older copy of the libxml2 XML processor that contains a known weakness. The flaw is in a command‑line tool…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
Versions of Nokogiri before 1.15.6 and before 1.16.2 can crash when they read XML files that use DTD validation and XInclude features. The problem occurs only with the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
Versions of Nokogiri before 1.15.6 and before 1.16.2 can crash when they read XML files that use DTD validation and XInclude features. The problem occurs only with the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
If your Ruby application uses Nokogiri older than version 1.13.2, specially when it processes XML or XSL files from outside sources, an attacker could cause the program to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
If your Ruby application uses Nokogiri older than version 1.13.2, specially when it processes XML or XSL files from outside sources, an attacker could cause the program to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#nokogiri #sparklemotion #CVE #infosec
CVE-2022-50999 CVSS 8.6 | HIGH
CVE-2022-50999 CVSS 8.6 | HIGH
CVE-2022-50998 CVSS 7.5 | HIGH
CVE-2022-50998 CVSS 7.5 | HIGH
CVE-2021-47996 CVSS 7.5 | HIGH
CVE-2021-47996 CVSS 7.5 | HIGH
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validat...
🔎 https://stemshop.top/cve/CVE-2025-71407
#CVE #CyberSecurity #InfoSec
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validat...
🔎 https://stemshop.top/cve/CVE-2025-71407
#CVE #CyberSecurity #InfoSec
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a u...
🔎 https://stemshop.top/cve/CVE-2024-58378
#CVE #CyberSecurity #InfoSec
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a u...
🔎 https://stemshop.top/cve/CVE-2024-58378
#CVE #CyberSecurity #InfoSec
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xml...
🔎 https://stemshop.top/cve/CVE-2024-58377
#CVE #CyberSecurity #InfoSec
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xml...
🔎 https://stemshop.top/cve/CVE-2024-58377
#CVE #CyberSecurity #InfoSec
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1...
🔎 https://stemshop.top/cve/CVE-2022-51000
#CVE #CyberSecurity #InfoSec
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1...
🔎 https://stemshop.top/cve/CVE-2022-51000
#CVE #CyberSecurity #InfoSec
The third week to Hota to go up Mt Nokogiri and to swim in Tokyo Bay.
Otherwise staying in Tokyo. @missmerc.bsky.social is taking me to see the Yakult Swallows on Saturday.
Tomorrow I might catch the last hanabi matsuri.
The third week to Hota to go up Mt Nokogiri and to swim in Tokyo Bay.
Otherwise staying in Tokyo. @missmerc.bsky.social is taking me to see the Yakult Swallows on Saturday.
Tomorrow I might catch the last hanabi matsuri.