rubygems

nokogiri

View on rubygems registry
62 Total advisories
62 Vulnerabilities
0 Malware

Dependency scanning

Check whether nokogiri is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
RubyGems

CVE-2026-57436

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

UNKNOWN
RubyGems

CVE-2026-57434

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

LOW 2.6
RubyGems

CVE-2026-57234

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

UNKNOWN
RubyGems

CVE-2026-57435

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

UNKNOWN
RubyGems

CVE-2026-57438

Nokogiri: Possible Use-After-Free in XInclude Processing

UNKNOWN
RubyGems

CVE-2026-57236

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

UNKNOWN
RubyGems

CVE-2026-57437

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

UNKNOWN
RubyGems

CVE-2026-57235

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

HIGH 7.5
RubyGems

CVE-2021-41098

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby

MEDIUM 4.3
RubyGems

CVE-2020-26247

Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

MEDIUM 5.3
RubyGems

CVE-2019-13117

Uninitialized read in Nokogiri gem

CRITICAL 9.8
RubyGems

CVE-2019-11068

Nokogiri vulnerable to libxslt protection mechanism bypass

HIGH 7.5
RubyGems

CVE-2019-13118

libxslt Type Confusion vulnerability that affects Nokogiri

HIGH 7.5
RubyGems

CVE-2019-18197

Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability

HIGH 7.5
RubyGems

GHSA-c4rq-3m3g-8wgx

Nokogiri CSS selector tokenizer has regular expression backtracking

MEDIUM 5.3
RubyGems

GHSA-v2fc-qm4h-8hqv

Nokogiri XSLT transform has a memory leak

MEDIUM 5.3
RubyGems

GHSA-wx95-c6cv-8532

Nokogiri does not check the return value from xmlC14NExecute

UNKNOWN
RubyGems

GHSA-r3w4-36x6-7r99

Duplicate Advisory: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

UNKNOWN
RubyGems

GHSA-r95h-9x8f-r3f7

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

HIGH 7.8
RubyGems

GHSA-mrxw-mxhj-p664

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

UNKNOWN
RubyGems

GHSA-vvfq-8hwr-qm4m

Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171

HIGH 7.5
RubyGems

CVE-2018-25032

Nokogiri affected by zlib's Out-of-bounds Write vulnerability

UNKNOWN
RubyGems

GHSA-353f-x4gh-cqq8

Nokogiri patches vendored libxml2 to resolve multiple CVEs

UNKNOWN
RubyGems

GHSA-5mwf-688x-mr7x

Duplicate Advisory: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171

UNKNOWN
RubyGems

GHSA-5w6v-399v-w3cc

Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415

UNKNOWN
RubyGems

GHSA-xc9x-jj77-9p9j

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

HIGH 7.5
RubyGems

CVE-2018-14404

Nokogiri NULL Pointer Dereference

LOW 3.3
RubyGems

GHSA-jc9r-qcgw-fxq9

sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow

LOW 3.3
RubyGems

GHSA-pf9w-gvcf-gv7m

sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow

HIGH 8.2
RubyGems

CVE-2022-29181

Nokogiri Improperly Handles Unexpected Data Type

UNKNOWN
RubyGems

GHSA-vcc3-rw6f-jv97

Duplicate Advisory: Use-after-free in libxml2 via Nokogiri::XML::Reader

UNKNOWN
RubyGems

CVE-2015-7499

Heap-based buffer overflow in nokogiri

HIGH 8.6
RubyGems

GHSA-cgx6-hpwq-fhv5

Integer Overflow or Wraparound in libxml2 affects Nokogiri

UNKNOWN
RubyGems

GHSA-fq42-c5rg-92c2

Vulnerable dependencies in Nokogiri

HIGH 7.5
RubyGems

GHSA-v6gp-9mmm-c6p5

Out-of-bounds Write in zlib affects Nokogiri

MEDIUM 6.5
RubyGems

GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

HIGH 7.5
RubyGems

GHSA-gx8x-g87m-h5q6

Denial of Service (DoS) in Nokogiri on JRuby

UNKNOWN
RubyGems

GHSA-pxvg-2qj5-37jq

Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs

UNKNOWN
RubyGems

GHSA-2qc6-mcvw-92cw

Update bundled libxml2 to v2.10.3 to resolve multiple CVEs

UNKNOWN
RubyGems

GHSA-7rrm-v45f-jp64

Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12

UNKNOWN
RubyGems

CVE-2015-1819

Nokogiri vulnerable to libxml XML Entity Expansion

UNKNOWN
RubyGems

CVE-2015-5312

Nokogiri subject to DoS via libxml2 vulnerability

HIGH 8.8
RubyGems

CVE-2021-3518

Nokogiri Implements libxml2 version vulnerable to use-after-free

HIGH 8.6
RubyGems

CVE-2021-3517

Nokogiri contains libxml Out-of-bounds Write vulnerability

HIGH 7.5
RubyGems

CVE-2020-7595

libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation

MEDIUM 6.1
RubyGems

CVE-2018-8048

Cross-site Scripting in loofah

HIGH 7.5
RubyGems

CVE-2017-16932

Nokogiri gem, via libxml, is affected by DoS vulnerabilities

MEDIUM 5.9
RubyGems

CVE-2021-3537

Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing

CRITICAL 9.8
RubyGems

CVE-2019-5477

Nokogiri Command Injection Vulnerability

MEDIUM 6.5
RubyGems

CVE-2013-6460

Nokogiri vulnerable to DoS while parsing XML documents

HIGH 7.5
RubyGems

CVE-2022-24836

Nokogiri Inefficient Regular Expression Complexity

HIGH 7.5
RubyGems

CVE-2019-5815

Nokogiri implementation of libxslt vulnerable to heap corruption

MEDIUM 6.5
RubyGems

CVE-2013-6461

Nokogiri vulnerable to DoS while parsing XML entities

CRITICAL 9.8
RubyGems

CVE-2016-4658

Nokogiri does not forbid namespace nodes in XPointer ranges

HIGH 7.5
RubyGems

CVE-2015-8806

Denial of service or RCE from libxml2 and libxslt

HIGH 8.8
RubyGems

CVE-2017-5029

Nokogiri implementation of libxslt lacks integer overflow checks

HIGH 8.8
RubyGems

CVE-2017-15412

Nokogiri gem, via libxml, is affected by DoS vulnerabilities

MEDIUM 6.5
RubyGems

CVE-2017-18258

Uncontrolled resource consumption in nokogiri

HIGH 8.8
RubyGems

CVE-2021-30560

Nokogiri has vulnerable dependencies on libxml2 and libxslt

HIGH 7.5
RubyGems

CVE-2022-23476

Unchecked return value from xmlTextReaderExpand

HIGH 7.5
RubyGems

CVE-2017-9050

Out-of-bounds read in nokogiri

HIGH 7.5
RubyGems

CVE-2012-6685

Nokogiri is vulnerable to XML External Entity (XXE) attack

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes