Launch Week Day 1: Announcing Security Design Review
HIGH 7.8 RubyGems

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

GHSA-mrxw-mxhj-p664

Published ยท Modified

Description

Summary

Nokogiri v1.18.4 upgrades its dependency libxslt to v1.1.43.

libxslt v1.1.43 resolves:

  • CVE-2025-24855: Fix use-after-free of XPath context node
  • CVE-2024-55549: Fix UAF related to excluded namespaces

Impact

CVE-2025-24855

CVE-2024-55549

Ready to move

Start Securing

Free, no credit card | First findings in minutes