---
cve: "CVE-2022-24839"
severity: "HIGH"
cvss: 7.5
epss: "2.2%"
vendor: "sparklemotion"
kev: false
exploited: false
published: "2022-04-11 21:25:12"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T00:41:56+02:00"
---

# CVE-2022-24839

> 7.5 HIGH · 🧪 PoC

## Beschreibung

org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 591ff8f41c75a70e66596567b03dbf671e7ade0d (Commit)
- a800fce3b079def130ed42a408ff1d09f89e773d (Commit)

## Referenzen

- <https://github.com/sparklemotion/nekohtml/security/advisories/GHSA-9849-p7jc-9rmv>
- <https://github.com/sparklemotion/nekohtml/commit/a800fce3b079def130ed42a408ff1d09f89e773d>
- <https://www.oracle.com/security-alerts/cpujul2022.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-24839) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
