PT-2026-81342 · Rubygems+1 · Nokogiri+1
CVE-2025-71346
·
Published
2025-04-21
·
Updated
2026-08-25
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nokogiri versions prior to 1.18.8
Description
Nokogiri includes a version of libxml2 that contains a heap-based buffer under-read (a condition where a program reads data before the beginning of a buffer in the heap memory) within the
xmlSchemaIDCFillNodeTables() function in xmlschemas.c. This issue occurs during validation against an untrusted XML Schema or when validating untrusted documents against trusted schemas that utilize xsd:keyref combined with recursively defined types that have additional identity constraints.Recommendations
Update Nokogiri to version 1.18.8 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokogiri
Libxml2