PT-2026-81340 · Rubygems+1 · Nokogiri+1

CVE-2024-58377

·

Published

2024-05-13

·

Updated

2026-08-28

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.16.5
Description Nokogiri bundles libxml2 version 2.12.6, which contains an issue within the xmllint tool. However, there is no impact to users as Nokogiri does not provide or expose the xmllint tool.
Recommendations Update Nokogiri to version 1.16.5 or later.

Exploit

Fix

Uncontrolled Search Path Element

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58377
GHSA-R95H-9X8F-R3F7

Affected Products

Nokogiri
Libxml2