{"id":"GHSA-wjv4-x9w8-wm3h","title":"Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type","summary":"Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type","severity":"low","cwe":["CWE-416"],"vendor":"nokogiri","product":"nokogiri","affected":["nokogiri < 1.19.4"],"patched":["nokogiri 1.19.4"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wjv4-x9w8-wm3h","references":[{"url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wjv4-x9w8-wm3h"},{"url":"https://github.com/advisories/GHSA-wjv4-x9w8-wm3h"}],"tags":["ghsa","rubygems"],"ingestedAt":"2026-06-22T15:52:21.090Z","ecosystem":"rubygems","slug":"GHSA-wjv4-x9w8-wm3h","body":"## Overview\n\n### Summary\n\n`Nokogiri::XML::Document#root=` validated only that the new root was a `Nokogiri::XML::Node`, allowing a DTD node to be set as the document root. The result is a heap use-after-free during garbage collection or finalization, leading to an invalid memory read or potentially a segfault.\n\nNokogiri 1.19.4 restricts `Document#root=` to element nodes, raising `TypeError` for any other node type.\n\nThis memory-safety issue affects only the CRuby implementation (libxml2). The JRuby implementation was not affected; the same input validation was added there for behavioral parity.\n\n### Severity\n\nThe Nokogiri maintainers have evaluated this as low severity. This is only triggered by a programming error. It requires application code to assign a non-element node such as a DTD as the document root via `Document#root=`. Nokogiri 1.19.4 now raises `TypeError` instead of allowing a use-after-free. It cannot be triggered by untrusted input or through normal use of the public API.\n\n### Mitigation\n\nUpgrade to Nokogiri 1.19.4 or later.\n\nAs a workaround, applications that cannot upgrade should avoid assigning a DTD (or any non-element node) via `Document#root=`.\n\n### Credit\n\nThis issue was responsibly reported by Zheng Yu from depthfirst.com.\n\n## Affected packages\n\n- `nokogiri < 1.19.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nokogiri 1.19.4`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}