VulnSea

nokogiri vulnerabilities

CVEs whose affected-version data names the nokogiri package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-79770High· 7.5
4w ago

Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods …

Twilightsparklemotion · nokogiriEPSS 0.28%via CVEORG
GHSA-5v8h-3h3q-446pLow
3mo ago

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Sunlitnokogiri · nokogirivia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Sunlitnokogiri · nokogirivia GHSA
GHSA-9cv2-cfxc-v4v2Low
3mo ago

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Sunlitnokogiri · nokogirivia GHSA
GHSA-5prr-v3j2-97mhMedium
3mo ago

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Sunlitnokogiri · nokogirivia GHSA
GHSA-wjv4-x9w8-wm3hLow
3mo ago

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Sunlitnokogiri · nokogirivia GHSA
GHSA-p67v-3w7g-wjg7Low
3mo ago

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Sunlitnokogiri · nokogirivia GHSA
GHSA-wfpw-mmfh-qq69Low
3mo ago

Nokogiri: Possible Use-After-Free in XInclude Processing

Nokogiri: Possible Use-After-Free in XInclude Processing

Sunlitnokogiri · nokogirivia GHSA
GHSA-phwj-rprq-35ppLow
3mo ago

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Sunlitnokogiri · nokogirivia GHSA
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Midnightnokogiri · nokogiriEPSS 52%via NVD
nokogiri vulnerabilities (CVEs) · VulnSea