PT-2026-52449 · Rubygems · Nokogiri

·

CVE-2026-57434

·

Published

2026-06-19

·

Updated

2026-06-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.19.4
Description Nokogiri contains a bug occurring when certain methods are called on native wrapper classes that inherit from Nokogiri::XML::Node and have been allocated but not initialized. This leads to a NULL pointer dereference, which is a condition where the software attempts to read from a memory address that is null, resulting in a process crash.
Recommendations Update to version 1.19.4.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91074
CVE-2026-57434
GHSA-9CV2-CFXC-V4V2

Affected Products

Nokogiri