PT-2026-81340 · Rubygems+1 · Nokogiri+1
CVE-2024-58377
·
Published
2024-05-13
·
Updated
2026-08-28
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nokogiri versions prior to 1.16.5
Description
Nokogiri bundles libxml2 version 2.12.6, which contains an issue within the xmllint tool. However, there is no impact to users as Nokogiri does not provide or expose the xmllint tool.
Recommendations
Update Nokogiri to version 1.16.5 or later.
Exploit
Fix
Uncontrolled Search Path Element
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokogiri
Libxml2