CVE-2024-58378
Nokogiri before 1.16.2 Use-After-Free via xmlTextReader
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
| CWE | CWE-416 |
| Vendor | sparklemotion |
| Product | nokogiri |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for sparklemotion nokogiri
Be the first to know when new critical vulnerabilities affecting sparklemotion nokogiri are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
sparklemotion / nokogiri
1.16.0 < 1.16.2
sparklemotion / nokogiri
0 < 1.15.6