๐Ÿ” CVE Alert

CVE-2021-47996

HIGH 7.5

Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.

CWE CWE-119
Vendor sparklemotion
Product nokogiri
Published Aug 25, 2026
Last Updated Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for sparklemotion nokogiri

Be the first to know when new high vulnerabilities affecting sparklemotion nokogiri are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

sparklemotion / nokogiri
0 < 1.11.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64 github.com: https://github.com/sparklemotion/nokogiri/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a github.com: https://github.com/sparklemotion/nokogiri/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5 github.com: https://github.com/sparklemotion/nokogiri/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2 github.com: https://github.com/sparklemotion/nokogiri/commit/1358d157d0bd83be1dfe356a69213df9fac0b539 github.com: https://github.com/sparklemotion/nokogiri/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2 github.com: https://github.com/sparklemotion/nokogiri/commit/1098c30a040e72a4654968547f415be4e4c40fe7 github.com: https://github.com/sparklemotion/nokogiri/commit/babe75030c7f64a37826bb3342317134568bef61 github.com: https://github.com/sparklemotion/nokogiri/commit/8598060bacada41a0eb09d95c97744ff4e428f8e vulncheck.com: https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-via-libxml2