PT-2026-52452 · Rubygems · Nokogiri

·

CVE-2026-57437

·

Published

2026-06-19

·

Updated

2026-06-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.19.4
Description In the Nokogiri XML and HTML library for Ruby, the Nokogiri::XML::XPathContext does not maintain a reference to its source document to prevent garbage collection. If an XPathContext persists after its associated document has been collected by the garbage collector, evaluating an XPath expression may result in reading invalid memory, potentially leading to a segmentation fault (segfault), which is a crash caused by accessing memory that the program is not allowed to access. This issue occurs only when application code directly instantiates an XPathContext and allows the document to become unreachable while the context is still in use. Standard search methods such as Document#xpath and Document#css are not affected, and the issue cannot be triggered via malicious document input.
Recommendations Update to version 1.19.4.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91071
CVE-2026-57437
GHSA-P67V-3W7G-WJG7

Affected Products

Nokogiri