PT-2026-81361 · Rubygems · Nokogiri
CVE-2026-79772
·
Published
2026-02-18
·
Updated
2026-08-28
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nokogiri versions prior to 1.19.1
Description
The
canonicalize method fails to check the return value from the xmlC14NExecute() function. When a failure occurs, the method returns an empty string instead of raising an exception. This behavior allows attackers to bypass signature validation in downstream SAML (Security Assertion Markup Language) libraries by providing invalid canonicalized XML that is incorrectly processed as valid.Recommendations
Update Nokogiri to version 1.19.1 or later.
Exploit
Fix
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokogiri