CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2018-25032

High · CVSS 7.5

zlib / nokogiri (RubyGems) — Out-of-bounds Write / Memory Corruption during deflate compression (CWE-787)

CVSS
7.5
nvd
EPSS
52.1%
99th pct
KEV
No
Class
oss containerizable
CWE-787, CWE-787

Description

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Search profile — drives PoC discovery

Symbols deflatezlibdeflateInitdeflateInit2compresscompress2deflateEndZ_DEFLATEDdistant matchesmatch_headstrstartlookahead
Keywords CVE-2018-25032zlib memory corruptionzlib deflate distant matcheszlib before 1.2.12nokogiri zlib CVE-2018-25032zlib out-of-bounds writezlib compression vulnerabilityzlib deflate exploitCWE-787 zlib
Versions: zlib < 1.2.12; nokogiri (all versions bundling zlib < 1.2.12)

Ranked PoCs (14) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

RubyGems nokogiri 0 → 1.13.4

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z