Nokogiri 1.18.8 之前的版本打包了存在漏洞的 libxml2 版本(低于 2.13.8),该版本在 xmlschemas.c 的 xmlSchemaIDCFillNodeTables 函数中包含一个基于堆的缓冲区下读漏洞(CVE-2025-32415)。当针对不受信任的 XML Schema 进行验证时,或在针对使用 xsd:keyref 与递归定义的、并带有额外身份约束类型的受信任 Schema 验证不受信任的文档时,可能会触发此问题。上游机构和 MITRE 均将该问题评级为低严重程度。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sparklemotion | nokogiri | < 1.18.8 |
affected |
1.18.8 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sparklemotion | nokogiri | 0 ~ 1.18.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58378 | 9.8 CRITICAL | Nokogiri before 1.16.2 Use-After-Free via xmlTextReader |
| CVE-2022-51000 | 9.8 CRITICAL | Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt |
| CVE-2025-71407 | 9.8 CRITICAL | Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free |
| CVE-2022-50999 | 8.6 HIGH | Nokogiri before 1.13.5 Integer Overflow via libxml2 |
| CVE-2025-71406 | 7.8 HIGH | Nokogiri before 1.18.4 Use-After-Free via libxslt |
| CVE-2023-54354 | 7.5 HIGH | Nokogiri before 1.14.3 Null Pointer Dereference via libxml2 |
| CVE-2026-79770 | 7.5 HIGH | Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer |
| CVE-2022-50998 | 7.5 HIGH | Nokogiri before 1.13.9 Multiple Vulnerabilities via libxml2 |
| CVE-2021-47996 | 7.5 HIGH | Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2 |
| CVE-2026-79769 | 5.5 MEDIUM | Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args |
| CVE-2026-79771 | 5.3 MEDIUM | Nokogiri before 1.19.3 Memory Leak via XSLT Transform |
| CVE-2026-79772 | 5.3 MEDIUM | Nokogiri before 1.19.1 Unchecked Return Value canonicalize |
| CVE-2024-58377 | Nokogiri before 1.16.5 libxml2 Dependency Update |
No comments yet