PT-2026-81343 · Git+4 · Nokogiri+1
CVE-2025-71406
·
Published
2025-03-14
·
Updated
2026-09-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
🚨 HIGH SEVERITY: CVE-2025-71406 (CVSS 7.8)
Nokogiri <1.18.4 bundles vulnerable libxslt with use-after-free flaws. Crafted XSLT can trigger memory corruption.
✅ Update to Nokogiri 1.18.4+
#CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/p57hvpONpW
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokogiri
Ruby-Nokogiri