Nokogiri
This hub aggregates every CVE we track for Nokogiri, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
42
CVEs tracked
3
Critical
22
High
0
In CISA KEV
Severity distribution
HIGH22MEDIUM13LOW4CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
8
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Nokogiri.
- CVE-2026-57438Nokogiri: Possible Use-After-Free in XInclude Processing6.6
- CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime5.3
- CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type5.3
- CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`7.5
- CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes7.5
- CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`8.2
- CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-262472.6
- CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception8.2
- CVE-2025-6494sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow3.3
- CVE-2025-6490sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow3.3
- CVE-2022-23476Unchecked return value from xmlTextReaderExpand in Nokogiri7.5
- CVE-2022-29181Improper Handling of Unexpected Data Type in Nokogiri8.2
- CVE-2022-24836Inefficient Regular Expression Complexity in Nokogiri7.5
- CVE-2018-25032zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.7.5
- CVE-2021-41098Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby7.5
Product normalization is registry-driven with AI assist and human review. How it works