{"id":"GHSA-5prr-v3j2-97mh","title":"Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`","summary":"Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`","severity":"medium","cwe":["CWE-125","CWE-190"],"vendor":"nokogiri","product":"nokogiri","affected":["nokogiri < 1.19.4"],"patched":["nokogiri 1.19.4"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5prr-v3j2-97mh","references":[{"url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5prr-v3j2-97mh"},{"url":"https://github.com/advisories/GHSA-5prr-v3j2-97mh"}],"tags":["ghsa","rubygems"],"ingestedAt":"2026-06-22T15:52:21.091Z","ecosystem":"rubygems","slug":"GHSA-5prr-v3j2-97mh","body":"## Overview\n\n### Summary\n\n`Nokogiri::XML::NodeSet#[]` (and its alias `#slice`) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby it is not memory-unsafe but returns an incorrect node.\n\nNokogiri 1.19.4 performs the bounds check against the full-width index.\n\n### Severity\n\nThe Nokogiri maintainers have evaluated this as medium severity.\n\nExploitation requires an application to pass an attacker-controlled integer to `NodeSet#[]`. The primary impact is a controlled crash (denial of service), with potential for memory disclosure on CRuby.\n\nOn JRuby, Nokogiri is not affected by this vulnerability.\n\n### Mitigation\n\nUpgrade to Nokogiri 1.19.4 or later.\n\nAs a workaround, applications that index a `NodeSet` with externally-supplied integers can validate the index against `node_set.length` before use, or avoid passing untrusted values as an index.\n\n### Credit\n\nThis issue was responsibly reported by Zheng Yu from depthfirst.com.\n\n## Affected packages\n\n- `nokogiri < 1.19.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nokogiri 1.19.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}