Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nokogiri — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in nokogiri, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the nokogiri library, focusing on common weakness classifications tracked by security vendors. It collects data regarding multiple vulnerability types, including cross-site scripting, path traversal, and buffer overflow issues, covering the period from 2010 through the present. By consolidating advisory data from various sources, this resource allows users to track vendor-specific announcements, understand the broader context of specific weakness classes affecting XML processing libraries, and look up the complete vulnerability history of the nokogiri product. The data includes details on severity scores, affected versions, and remediation status to help developers and security professionals assess risk. Users can filter results by date, severity, or vulnerability type to identify relevant threats. This compilation aids in maintaining software integrity by providing a centralized view of known defects. It supports compliance and risk management efforts by offering historical context for security audits. The information is updated regularly to reflect newly disclosed issues. Accessing this data helps in prioritizing patching efforts based on the actual exposure of the nokogiri installation within an organization. The page serves as a reference for understanding the evolution of security issues within this popular Ruby library.

Vendor: sparklemotion

CVE ID Title CVSS Severity Published
CVE-2026-79772 Nokogiri before 1.19.1 Unchecked Return Value canonicalize CWE-252 5.3 Medium 2026-08-25
CVE-2026-79771 Nokogiri before 1.19.3 Memory Leak via XSLT Transform CWE-401 5.3 Medium 2026-08-25
CVE-2026-79770 Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer CWE-1333 7.5 High 2026-08-25
CVE-2026-79769 Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args CWE-843 5.5 Medium 2026-08-25
CVE-2026-57438 Nokogiri: Possible Use-After-Free in XInclude Processing CWE-416 - - 2026-06-25
CVE-2026-57437 Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime CWE-416 - - 2026-06-25
CVE-2026-57436 Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type CWE-416 - - 2026-06-25
CVE-2026-57435 Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` CWE-416 - - 2026-06-25
CVE-2026-57434 Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes CWE-476 - - 2026-06-25
CVE-2026-57235 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` CWE-125 - - 2026-06-25
CVE-2026-57234 Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 CWE-178 2.6 Low 2026-06-25
CVE-2026-57236 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception CWE-416 - - 2026-06-25
CVE-2025-6494 sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow CWE-122 3.3 Low 2025-06-22
CVE-2025-6490 sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow CWE-122 3.3 Low 2025-06-22
CVE-2022-23476 Unchecked return value from xmlTextReaderExpand in Nokogiri CWE-252 7.5 High 2022-12-08
CVE-2022-29181 Improper Handling of Unexpected Data Type in Nokogiri CWE-241 8.2 High 2022-05-20
CVE-2022-24836 Inefficient Regular Expression Complexity in Nokogiri CWE-400 7.5 High 2022-04-11
CVE-2021-41098 Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby CWE-611 7.5 - 2021-09-27
CVE-2020-26247 XXE in Nokogiri CWE-611 2.6 Low 2020-12-30

All 19 known CVE vulnerabilities affecting nokogiri with full Chinese analysis, references, and POCs where available.