Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2024-58378: Nokogiri update fixes XML parsing vulnerability in libxml2

CVE-2024-58378 · published 9 days ago
Summary

A security update for Nokogiri fixes a vulnerability that could be exploited by malicious XML documents. This affects users of the packaged version of Nokogiri, not those who use system libraries. To stay secure, update to Nokogiri version 1.15.6 or later.

What to do
  • Update mike dalessio nokogiri to version 1.16.2.
  • Update mike dalessio nokogiri to version 1.15.6.
Affected software
Ecosystem VendorProductAffected versions
rubygems mike dalessio nokogiri >= 1.16.0, < 1.16.2
< 1.15.6
Fix: upgrade to 1.16.2
– sparklemotion nokogiri < 1.16.2
< 1.15.6
Original advisory text
Nokogiri before 1.16.2 Use-After-Free via xmlTextReader
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Severity
9.9 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen6 Mar 2026
Sources
CVE-2024-58378 · MITRE
Monitor software like this
Free during beta