Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2025-71407: Nokogiri can crash or be hijacked by crafted XML

CVE-2025-71407 · published 9 days ago
Summary

The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML definitions from untrusted sources. This could let an attacker shut down your application or take control of it. Update Nokogiri to version 1.18.3 or newer to fix the problem.

What to do
  • Update sparklemotion nokogiri to version 1.18.3 or later.
Affected software
VendorProductAffected versions
sparklemotion nokogiri < 1.18.3
Original advisory text
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation ...
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-787Out-of-bounds Write
Timeline
Published25 Aug 2026
Updated30 Aug 2026
First seen25 Aug 2026
Sources
CVE-2025-71407 · MITRE
Monitor software like this
Free during beta