{"id":"CVE-2022-21144","summary":"Denial of Service (DoS)","details":"This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.","aliases":["GHSA-773h-w45w-f2f9","SNYK-JS-LIBXMLJS-2348756"],"modified":"2026-07-09T14:43:48.239954Z","published":"2022-05-01T15:25:10.325Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21144.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"0"}]}],"cna_assigner":"snyk"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21144.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21144"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-LIBXMLJS-2348756"},{"type":"FIX","url":"https://github.com/libxmljs/libxmljs/commit/2501807bde9b38cfaed06d1e140487516d91379d"},{"type":"FIX","url":"https://github.com/libxmljs/libxmljs/pull/594"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libxmljs/libxmljs","events":[{"introduced":"0"},{"fixed":"27c90841c67b60430c7064c74567a2bfb1d9a2fd"},{"fixed":"2501807bde9b38cfaed06d1e140487516d91379d"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:libxmljs_project:libxmljs:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.19.8"}]}}],"versions":["v0.19.7","v0.19.6","v0.19.5","v0.19.4","v0.19.3","v0.19.2","v0.19.0","v0.18.8","v0.18.7","v0.18.6","v0.18.5","v0.18.4","v0.18.3","v0.18.2","v0.18.1","v0.18.0","v0.17.1","v0.17.0","v0.16.1","v0.16.0","v0.15.0","v0.14.3","v0.14.2","v0.14.1","v0.14.0","v0.13.0","v0.12.0","v0.11.1","v0.11.0","v0.10.0","v0.9.0","v0.8.1","v0.8.0","v0.7.0","v0.6.1","v0.6.0","0.5.4","0.5.3","0.5.2","0.5.1","0.5.0","0.4.3","0.4.1","0.4.0","0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21144.json","vanir_signatures":[{"deprecated":false,"signature_version":"v1","id":"CVE-2022-21144-88512d45","target":{"function":"NAN_METHOD","file":"src/xml_document.cc"},"source":"https://github.com/libxmljs/libxmljs/commit/2501807bde9b38cfaed06d1e140487516d91379d","digest":{"length":2195,"function_hash":"107727053438835856466343391473296274860"},"signature_type":"Function"},{"deprecated":false,"signature_version":"v1","id":"CVE-2022-21144-8a89c841","target":{"function":"NAN_METHOD","file":"src/xml_document.cc"},"source":"https://github.com/libxmljs/libxmljs/commit/2501807bde9b38cfaed06d1e140487516d91379d","digest":{"length":1991,"function_hash":"136495662352428680651636031310365647788"},"signature_type":"Function"},{"deprecated":false,"signature_version":"v1","id":"CVE-2022-21144-fe153aa8","target":{"file":"src/xml_document.cc"},"source":"https://github.com/libxmljs/libxmljs/commit/2501807bde9b38cfaed06d1e140487516d91379d","digest":{"threshold":0.9,"line_hashes":["249851446725122353917134027082104187227","22987054179427781354923844765744493052","92194844220785061289742511096799865613","103842121778067350803698352097324791962","332784255652129248409588464678968976521","118809179461203962188333144776721377647","45923624500783531127707131557921849567","59052600784026491515100570822628383145","206601563682319210915043524735815572577","106256515466840548357998428534562107609","72138142820922648892957219895867383571","37960217532412656122514148666667480580","189025941815283442878199660578987685468","252111081753236280706835628782424485411","195484571969083763760934305661801188029","209151954169205677479930319915944360268","102790475236216434001478899527197655571","292101194238850167358375657424650220425","320837122313242282543495271834571493611","237463097973166374882058319490188168492","325800957678461270556465086366463336358","72138142820922648892957219895867383571"]},"signature_type":"Line"}],"vanir_signatures_modified":"2026-07-09T14:43:48Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P"}]}