PT-2026-81339 · Rubygems+1 · Nokogiri+1

CVE-2023-54354

·

Published

2023-04-11

·

Updated

2026-08-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.14.3
Description The CRuby implementation, when using the packaged libxml2 v2.10.3, contains a flaw in XML Schema processing. An attacker can provide a crafted or malformed XML schema to trigger NULL pointer dereferences within the xmlSchemaFixupComplexType() and xmlSchemaCheckCOSSTDerivedOK() functions. This can lead to a segmentation fault, resulting in a denial of service.
Recommendations Update to version 1.14.3 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54354
GHSA-PXVG-2QJ5-37JQ

Affected Products

Nokogiri
Libxml2