Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

CVE-2024-58377: Nokogiri < 1.16.5 includes vulnerable libxml2 library

CVE-2024-58377 · published 1 month ago
Summary

Versions of the Nokogiri Ruby library released before 1.16.5 contain an older copy of the libxml2 component that has a known weakness in its xmllint utility. The weakness matters only if that utility is made available, which Nokogiri does not expose, so ordinary users are not directly at risk. Updating Nokogiri to version 1.16.5 or later replaces the component with a safe version.

What to do
  • Update mike dalessio nokogiri to version 1.16.5.
  • Update sparklemotion nokogiri to version 1.16.5 or later.
  • Update nokogiri nokogiri to version 1.16.5 or later.
Affected software
Ecosystem VendorProductAffected versions
rubygems mike dalessio nokogiri < 1.16.5
Fix: upgrade to 1.16.5
– sparklemotion nokogiri < 1.16.5
– nokogiri nokogiri < 1.16.5
cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:*
Ubuntu:Pro:14.04:LTS canonical ruby-nokogiri All versions
Original advisory text
Nokogiri before 1.16.5 libxml2 Dependency Update
Rejected reason: This CVE ID has been rejected as a duplicate.
Severity
7.3 High
CVSS 3.1: 0.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
CWE-427Uncontrolled Search Path Element
CWE-125Out-of-bounds Read
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta