nokogiri
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting nokogiri.
- CVE-2026-57438Nokogiri: Possible Use-After-Free in XInclude Processing6.6
- CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime5.3
- CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type5.3
- CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`7.5
- CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes7.5
- CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`8.2
- CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-262472.6
- CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception8.2
- CVE-2022-23476Unchecked return value from xmlTextReaderExpand in Nokogiri7.5
- CVE-2022-29181Improper Handling of Unexpected Data Type in Nokogiri8.2
- CVE-2022-24836Inefficient Regular Expression Complexity in Nokogiri7.5
- CVE-2018-25032zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.7.5
- CVE-2021-41098Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby7.5
- CVE-2020-26247XXE in Nokogiri2.6
- CVE-2012-6685Nokogiri before 1.5.4 is vulnerable to XXE attacks7.5