Dependency scanning
Check whether nokogiri is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
GHSA-xqqh-3w52-q8p7
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
GHSA-rh9x-7xjc-vwx2
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
CVE-2026-57438
Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2025-6490
sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
CVE-2025-6494
sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow
CVE-2025-71406
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
GHSA-5jhf-fpp7-v2pv
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
CVE-2026-57436
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-57236
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
CVE-2026-79771
Nokogiri XSLT transform has a memory leak
CVE-2026-79770
Nokogiri CSS selector tokenizer has regular expression backtracking
CVE-2026-79772
Nokogiri does not check the return value from xmlC14NExecute
GHSA-353f-x4gh-cqq8
Nokogiri patches vendored libxml2 to resolve multiple CVEs
CVE-2025-71346
Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415
GHSA-5mwf-688x-mr7x
Duplicate Advisory: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
CVE-2025-71407
Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
CVE-2018-25032
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
CVE-2021-47996
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
CVE-2024-58378
Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
CVE-2024-58377
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
CVE-2022-50999
Integer Overflow or Wraparound in libxml2 affects Nokogiri
CVE-2023-54354
Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs
CVE-2022-51000
Vulnerable dependencies in Nokogiri
CVE-2022-50998
Update bundled libxml2 to v2.10.3 to resolve multiple CVEs
GHSA-r3w4-36x6-7r99
Duplicate Advisory: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
CVE-2021-41098
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
CVE-2020-26247
Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability
CVE-2019-13117
Uninitialized read in Nokogiri gem
CVE-2019-11068
Nokogiri vulnerable to libxslt protection mechanism bypass
CVE-2019-13118
libxslt Type Confusion vulnerability that affects Nokogiri
CVE-2019-18197
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
CVE-2018-14404
Nokogiri NULL Pointer Dereference
CVE-2022-29181
Nokogiri Improperly Handles Unexpected Data Type
GHSA-vcc3-rw6f-jv97
Duplicate Advisory: Use-after-free in libxml2 via Nokogiri::XML::Reader
CVE-2015-7499
Heap-based buffer overflow in nokogiri
GHSA-v6gp-9mmm-c6p5
Out-of-bounds Write in zlib affects Nokogiri
GHSA-xxx9-3xcr-gjj3
XML Injection in Xerces Java affects Nokogiri
GHSA-gx8x-g87m-h5q6
Denial of Service (DoS) in Nokogiri on JRuby
CVE-2015-1819
Nokogiri vulnerable to libxml XML Entity Expansion
CVE-2015-5312
Nokogiri subject to DoS via libxml2 vulnerability
CVE-2021-3518
Nokogiri Implements libxml2 version vulnerable to use-after-free
CVE-2021-3517
Nokogiri contains libxml Out-of-bounds Write vulnerability
CVE-2020-7595
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
CVE-2018-8048
Cross-site Scripting in loofah
CVE-2017-16932
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
CVE-2021-3537
Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
CVE-2019-5477
Nokogiri Command Injection Vulnerability
CVE-2013-6460
Nokogiri vulnerable to DoS while parsing XML documents
CVE-2022-24836
Nokogiri Inefficient Regular Expression Complexity
CVE-2019-5815
Nokogiri implementation of libxslt vulnerable to heap corruption
CVE-2013-6461
Nokogiri vulnerable to DoS while parsing XML entities
CVE-2016-4658
Nokogiri does not forbid namespace nodes in XPointer ranges
CVE-2015-8806
Denial of service or RCE from libxml2 and libxslt
CVE-2017-5029
Nokogiri implementation of libxslt lacks integer overflow checks
CVE-2017-15412
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
CVE-2017-18258
Uncontrolled resource consumption in nokogiri
CVE-2021-30560
Nokogiri has vulnerable dependencies on libxml2 and libxslt
CVE-2022-23476
Unchecked return value from xmlTextReaderExpand
CVE-2017-9050
Out-of-bounds read in nokogiri
CVE-2012-6685
Nokogiri is vulnerable to XML External Entity (XXE) attack
Browse more RubyGems advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes