CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.
| CWE | CWE-476 |
| Vendor | sparklemotion |
| Product | nokogiri |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for sparklemotion nokogiri
Be the first to know when new unknown vulnerabilities affecting sparklemotion nokogiri are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sparklemotion / nokogiri
< 1.19.4