PT-2026-81361 · Rubygems · Nokogiri

CVE-2026-79772

·

Published

2026-02-18

·

Updated

2026-08-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.19.1
Description The canonicalize method fails to check the return value from the xmlC14NExecute() function. When a failure occurs, the method returns an empty string instead of raising an exception. This behavior allows attackers to bypass signature validation in downstream SAML (Security Assertion Markup Language) libraries by providing invalid canonicalized XML that is incorrectly processed as valid.
Recommendations Update Nokogiri to version 1.19.1 or later.

Exploit

Fix

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79772
GHSA-WX95-C6CV-8532
GHSA-XQQH-3W52-Q8P7

Affected Products

Nokogiri