---
id: GHSA-wjv4-x9w8-wm3h
title: >-
  Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid
  node type
summary: >-
  Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid
  node type
severity: low
cwe:
  - CWE-416
vendor: nokogiri
product: nokogiri
affected:
  - nokogiri < 1.19.4
patched:
  - nokogiri 1.19.4
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wjv4-x9w8-wm3h'
references:
  - url: >-
      https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wjv4-x9w8-wm3h
  - url: 'https://github.com/advisories/GHSA-wjv4-x9w8-wm3h'
tags:
  - ghsa
  - rubygems
ingestedAt: '2026-06-22T15:52:21.090Z'
ecosystem: rubygems
---

## Overview

### Summary

`Nokogiri::XML::Document#root=` validated only that the new root was a `Nokogiri::XML::Node`, allowing a DTD node to be set as the document root. The result is a heap use-after-free during garbage collection or finalization, leading to an invalid memory read or potentially a segfault.

Nokogiri 1.19.4 restricts `Document#root=` to element nodes, raising `TypeError` for any other node type.

This memory-safety issue affects only the CRuby implementation (libxml2). The JRuby implementation was not affected; the same input validation was added there for behavioral parity.

### Severity

The Nokogiri maintainers have evaluated this as low severity. This is only triggered by a programming error. It requires application code to assign a non-element node such as a DTD as the document root via `Document#root=`. Nokogiri 1.19.4 now raises `TypeError` instead of allowing a use-after-free. It cannot be triggered by untrusted input or through normal use of the public API.

### Mitigation

Upgrade to Nokogiri 1.19.4 or later.

As a workaround, applications that cannot upgrade should avoid assigning a DTD (or any non-element node) via `Document#root=`.

### Credit

This issue was responsibly reported by Zheng Yu from depthfirst.com.

## Affected packages

- `nokogiri < 1.19.4`

## Remediation

Upgrade to a patched release:

- `nokogiri 1.19.4`
