nokogiri has 9 CVEs on record between 2022 and 2026. Disclosures have slowed: 0 in the last 90 days after 8 in the 90 before. The busiest recent month was June 2026 with 8. The median CVSS is 5.0 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-416 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 8
Worst active — by depth score
CVE-2018-25032High· 7.5zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.64GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`28GHSA-wjv4-x9w8-wm3hLowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type14GHSA-wfpw-mmfh-qq69LowNokogiri: Possible Use-After-Free in XInclude Processing14GHSA-phwj-rprq-35ppLowNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`14
nokogiri vulnerabilities
CVEs affecting nokogiri, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
GHSA-5v8h-3h3q-446pLowNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
GHSA-8678-w3jw-xfc2Low· 2.6Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
GHSA-9cv2-cfxc-v4v2LowNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
GHSA-wjv4-x9w8-wm3hLowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
GHSA-p67v-3w7g-wjg7LowNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
GHSA-wfpw-mmfh-qq69LowNokogiri: Possible Use-After-Free in XInclude Processing
Nokogiri: Possible Use-After-Free in XInclude Processing
GHSA-phwj-rprq-35ppLowNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2018-25032High· 7.5PoCzlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.