VulnSea

nokogiri has 9 CVEs on record between 2022 and 2026. Disclosures have slowed: 0 in the last 90 days after 8 in the 90 before. The busiest recent month was June 2026 with 8. The median CVSS is 5.0 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-416 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.0
Publish → KEV
Last 90 days
0 prev 8

Products

  • nokogiri 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

nokogiri vulnerabilities

CVEs affecting nokogiri, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

GHSA-5v8h-3h3q-446pLow
3mo ago

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Sunlitnokogiri · nokogirivia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Sunlitnokogiri · nokogirivia GHSA
GHSA-9cv2-cfxc-v4v2Low
3mo ago

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Sunlitnokogiri · nokogirivia GHSA
GHSA-5prr-v3j2-97mhMedium
3mo ago

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Sunlitnokogiri · nokogirivia GHSA
GHSA-wjv4-x9w8-wm3hLow
3mo ago

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Sunlitnokogiri · nokogirivia GHSA
GHSA-p67v-3w7g-wjg7Low
3mo ago

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Sunlitnokogiri · nokogirivia GHSA
GHSA-wfpw-mmfh-qq69Low
3mo ago

Nokogiri: Possible Use-After-Free in XInclude Processing

Nokogiri: Possible Use-After-Free in XInclude Processing

Sunlitnokogiri · nokogirivia GHSA
GHSA-phwj-rprq-35ppLow
3mo ago

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Sunlitnokogiri · nokogirivia GHSA
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Midnightnokogiri · nokogiriEPSS 52%via NVD
nokogiri vulnerabilities (CVEs) · VulnSea