Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
CVE-2024-58377: Nokogiri < 1.16.5 includes vulnerable libxml2 library
CVE-2024-58377 · published 1 month ago
Summary
Versions of the Nokogiri Ruby library released before 1.16.5 contain an older copy of the libxml2 component that has a known weakness in its xmllint utility. The weakness matters only if that utility is made available, which Nokogiri does not expose, so ordinary users are not directly at risk. Updating Nokogiri to version 1.16.5 or later replaces the component with a safe version.
What to do
- Update mike dalessio nokogiri to version 1.16.5.
- Update sparklemotion nokogiri to version 1.16.5 or later.
- Update nokogiri nokogiri to version 1.16.5 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| rubygems | mike dalessio | nokogiri |
< 1.16.5 Fix: upgrade to 1.16.5
|
| – | sparklemotion | nokogiri | < 1.16.5 |
| – | nokogiri | nokogiri |
< 1.16.5 cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:* |
| Ubuntu:Pro:14.04:LTS | canonical | ruby-nokogiri | All versions |
Original advisory text
Nokogiri before 1.16.5 libxml2 Dependency Update
Rejected reason: This CVE ID has been rejected as a duplicate.
References
- https://github.com/sparklemotion/nokogiri/releases/tag/v1.16.5
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/2876ac53
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/720
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/GHSA-r95h-...
- https://github.com/advisories/GHSA-r95h-9x8f-r3f7
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58377... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-58377 Vendor Advisory
- https://www.vulncheck.com/advisories/nokogiri-before-libxml2-dependency-update Third Party Advisory
- https://github.com/GNOME/libxml2/commit/2876ac53 Third Party Advisory
- https://github.com/sparklemotion/nokogiri/commit/2876ac53 Patch
- https://ubuntu.com/security/CVE-2024-58377 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-58377 Third Party Advisory
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-r95h-9x8f-r3f... Third Party Advisory
Severity
7.3
High
CVSS 3.1: 0.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
CWE-427Uncontrolled Search Path Element
CWE-125Out-of-bounds Read
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen6 Mar 2026
Sources
CVE-2024-58377 · MITRE
CVE-2024-58377 · NVD
GHSA-r95h-9x8f-r3f7 · GHSA
CVE-2024-58377 · OSV
UBUNTU-CVE-2024-58377 · OSV
Track software like this
Free during beta