Dependency scanning
Check whether nokogiri is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-57436
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-57438
Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-57236
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2021-41098
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
CVE-2020-26247
Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability
CVE-2019-13117
Uninitialized read in Nokogiri gem
CVE-2019-11068
Nokogiri vulnerable to libxslt protection mechanism bypass
CVE-2019-13118
libxslt Type Confusion vulnerability that affects Nokogiri
CVE-2019-18197
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
GHSA-c4rq-3m3g-8wgx
Nokogiri CSS selector tokenizer has regular expression backtracking
GHSA-v2fc-qm4h-8hqv
Nokogiri XSLT transform has a memory leak
GHSA-wx95-c6cv-8532
Nokogiri does not check the return value from xmlC14NExecute
GHSA-r3w4-36x6-7r99
Duplicate Advisory: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
GHSA-r95h-9x8f-r3f7
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
GHSA-mrxw-mxhj-p664
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
GHSA-vvfq-8hwr-qm4m
Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
CVE-2018-25032
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
GHSA-353f-x4gh-cqq8
Nokogiri patches vendored libxml2 to resolve multiple CVEs
GHSA-5mwf-688x-mr7x
Duplicate Advisory: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
GHSA-5w6v-399v-w3cc
Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415
GHSA-xc9x-jj77-9p9j
Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
CVE-2018-14404
Nokogiri NULL Pointer Dereference
GHSA-jc9r-qcgw-fxq9
sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow
GHSA-pf9w-gvcf-gv7m
sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
CVE-2022-29181
Nokogiri Improperly Handles Unexpected Data Type
GHSA-vcc3-rw6f-jv97
Duplicate Advisory: Use-after-free in libxml2 via Nokogiri::XML::Reader
CVE-2015-7499
Heap-based buffer overflow in nokogiri
GHSA-cgx6-hpwq-fhv5
Integer Overflow or Wraparound in libxml2 affects Nokogiri
GHSA-fq42-c5rg-92c2
Vulnerable dependencies in Nokogiri
GHSA-v6gp-9mmm-c6p5
Out-of-bounds Write in zlib affects Nokogiri
GHSA-xxx9-3xcr-gjj3
XML Injection in Xerces Java affects Nokogiri
GHSA-gx8x-g87m-h5q6
Denial of Service (DoS) in Nokogiri on JRuby
GHSA-pxvg-2qj5-37jq
Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs
GHSA-2qc6-mcvw-92cw
Update bundled libxml2 to v2.10.3 to resolve multiple CVEs
GHSA-7rrm-v45f-jp64
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
CVE-2015-1819
Nokogiri vulnerable to libxml XML Entity Expansion
CVE-2015-5312
Nokogiri subject to DoS via libxml2 vulnerability
CVE-2021-3518
Nokogiri Implements libxml2 version vulnerable to use-after-free
CVE-2021-3517
Nokogiri contains libxml Out-of-bounds Write vulnerability
CVE-2020-7595
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
CVE-2018-8048
Cross-site Scripting in loofah
CVE-2017-16932
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
CVE-2021-3537
Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
CVE-2019-5477
Nokogiri Command Injection Vulnerability
CVE-2013-6460
Nokogiri vulnerable to DoS while parsing XML documents
CVE-2022-24836
Nokogiri Inefficient Regular Expression Complexity
CVE-2019-5815
Nokogiri implementation of libxslt vulnerable to heap corruption
CVE-2013-6461
Nokogiri vulnerable to DoS while parsing XML entities
CVE-2016-4658
Nokogiri does not forbid namespace nodes in XPointer ranges
CVE-2015-8806
Denial of service or RCE from libxml2 and libxslt
CVE-2017-5029
Nokogiri implementation of libxslt lacks integer overflow checks
CVE-2017-15412
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
CVE-2017-18258
Uncontrolled resource consumption in nokogiri
CVE-2021-30560
Nokogiri has vulnerable dependencies on libxml2 and libxslt
CVE-2022-23476
Unchecked return value from xmlTextReaderExpand
CVE-2017-9050
Out-of-bounds read in nokogiri
CVE-2012-6685
Nokogiri is vulnerable to XML External Entity (XXE) attack
Browse more RubyGems advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes