๐Ÿ” CVE Alert

CVE-2025-71346

LOW 2.9

Nokogiri before 1.18.8 Heap Buffer Under-read via XML Schema

CVSS Score
2.9
EPSS Score
0.0%
EPSS Percentile
0th

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity.

CWE CWE-125
Vendor sparklemotion
Product nokogiri
Published Aug 25, 2026
Last Updated Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for sparklemotion nokogiri

Be the first to know when new low vulnerabilities affecting sparklemotion nokogiri are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

sparklemotion / nokogiri
0 < 1.18.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5w6v-399v-w3cc vulncheck.com: https://www.vulncheck.com/advisories/nokogiri-before-heap-buffer-under-read-via-xml-schema