Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

sparklemotion — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting sparklemotion. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Sparklemotion develops interactive web applications with a focus on user engagement platforms. Historically, the organization has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and misconfigured access controls. Notable security characteristics include inconsistent patch management and inadequate dependency vetting, leading to multiple high-severity flaws. While no major public incidents have been documented, the accumulation of 10 CVEs suggests systemic security challenges in their development lifecycle. Their products remain attractive targets due to widespread deployment in customer-facing environments, necessitating improved security practices to mitigate persistent risks.

CVE ID Title CVSS Severity Published
CVE-2026-107715 Mechanize sends credential headers to another host after an HTTP redirect — mechanize CWE-200 6.8 Medium 2026-10-08
CVE-2026-107714 Mechanize sends credential headers to a different scheme or port after a redirect — mechanize CWE-200 5.9 Medium 2026-10-08
CVE-2026-107399 Mechanize sends credential headers to another origin after a meta refresh — mechanize CWE-200 6.8 Medium 2026-10-08
CVE-2026-79772 Nokogiri before 1.19.1 Unchecked Return Value canonicalize — nokogiri CWE-252 5.3 Medium 2026-08-25
CVE-2026-79771 Nokogiri before 1.19.3 Memory Leak via XSLT Transform — nokogiri CWE-401 5.3 Medium 2026-08-25
CVE-2026-79770 Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer — nokogiri CWE-1333 7.5 High 2026-08-25
CVE-2026-79769 Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args — nokogiri CWE-843 5.5 Medium 2026-08-25
CVE-2026-54620 sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks — sqlite3-ruby CWE-416 2.0 Low 2026-07-28
CVE-2026-54619 sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity — sqlite3-ruby CWE-416 2.0 Low 2026-07-28
CVE-2026-57438 Nokogiri: Possible Use-After-Free in XInclude Processing — nokogiri CWE-416 - - 2026-06-25
CVE-2026-57437 Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime — nokogiri CWE-416 - - 2026-06-25
CVE-2026-57436 Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type — nokogiri CWE-416 - - 2026-06-25
CVE-2026-57435 Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` — nokogiri CWE-416 - - 2026-06-25
CVE-2026-57434 Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes — nokogiri CWE-476 - - 2026-06-25
CVE-2026-57235 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` — nokogiri CWE-125 - - 2026-06-25
CVE-2026-57234 Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 — nokogiri CWE-178 2.6 Low 2026-06-25
CVE-2026-57236 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception — nokogiri CWE-416 - - 2026-06-25
CVE-2025-6494 sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow — nokogiri CWE-122 3.3 Low 2025-06-22
CVE-2025-6490 sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow — nokogiri CWE-122 3.3 Low 2025-06-22
CVE-2022-23476 Unchecked return value from xmlTextReaderExpand in Nokogiri — nokogiri CWE-252 7.5 High 2022-12-08
CVE-2022-31033 Authorization header leak in rubygem Mechanize — mechanize CWE-200 5.9 Medium 2022-06-09
CVE-2022-29181 Improper Handling of Unexpected Data Type in Nokogiri — nokogiri CWE-241 8.2 High 2022-05-20
CVE-2022-24839 Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork) — nekohtml CWE-400 7.5 High 2022-04-11
CVE-2022-24836 Inefficient Regular Expression Complexity in Nokogiri — nokogiri CWE-400 7.5 High 2022-04-11
CVE-2021-41098 Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby — nokogiri CWE-611 7.5 - 2021-09-27
CVE-2021-21289 Command Injection Vulnerability in Mechanize — mechanize CWE-78 7.4 High 2021-02-02
CVE-2020-26247 XXE in Nokogiri — nokogiri CWE-611 2.6 Low 2020-12-30

This page lists every published CVE security advisory associated with sparklemotion. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.