Medium severity6.5NVD Advisory· Published Nov 5, 2019· Updated Jun 17, 2026
CVE-2013-6460
CVE-2013-6460
Description
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nokogiriRubyGems | >= 1.5.0, < 1.5.11 | 1.5.11 |
nokogiriRubyGems | >= 1.6.0, < 1.6.1 | 1.6.1 |
Affected products
12- cpe:2.3:a:redhat:cloudforms_management_engine:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:subscription_asset_manager:-:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
- Ruby/Nokogiri gemv5Range: 1.5.x
Patches
Vulnerability mechanics
References
11- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2013/12/27/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/64513nvdThird Party AdvisoryVDB Entry
- access.redhat.com/security/cve/cve-2013-6460nvdThird Party AdvisoryWEB
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/90058nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-62qp-3fxm-9wxfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-6460ghsaADVISORY
- security-tracker.debian.org/tracker/CVE-2013-6460nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2013-6460.ymlghsaWEB
- web.archive.org/web/20200229074427/https://www.securityfocus.com/bid/64513ghsaWEB
News mentions
0No linked articles in our index yet.