PT-2026-81344 · Rubygems · Nokogiri

CVE-2025-71407

·

Published

2025-02-18

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.18.3
Description Nokogiri contains memory corruption issues within its bundled libxml2. A stack buffer overflow occurs when reporting DTD validation errors involving long QName prefixes. Additionally, a use-after-free condition exists during validation against untrusted XML Schemas (XSD). These issues can be triggered by providing malicious DTD content or untrusted XSD files during XML parsing and validation, potentially leading to a denial of service or remote code execution. Non-validating XML parsing is not affected.
Recommendations Update Nokogiri to version 1.18.3.

Exploit

Fix

RCE

Use After Free

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71407
GHSA-VVFQ-8HWR-QM4M

Affected Products

Nokogiri