PT-2026-81344 · Rubygems · Nokogiri
CVE-2025-71407
·
Published
2025-02-18
·
Updated
2026-08-30
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nokogiri versions prior to 1.18.3
Description
Nokogiri contains memory corruption issues within its bundled libxml2. A stack buffer overflow occurs when reporting DTD validation errors involving long QName prefixes. Additionally, a use-after-free condition exists during validation against untrusted XML Schemas (XSD). These issues can be triggered by providing malicious DTD content or untrusted XSD files during XML parsing and validation, potentially leading to a denial of service or remote code execution. Non-validating XML parsing is not affected.
Recommendations
Update Nokogiri to version 1.18.3.
Exploit
Fix
RCE
Use After Free
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokogiri