Nokogiri
71 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Nokogiri, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Nokogiri CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 1 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 2 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 16 |
| 2026-07 | 0 |
| 2026-08 | 4 |
| 2026-09 | 0 |
Severity
How the 71 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High23
- Medium16
- Low4
Latest CVEs
The 15 most recently published vulnerabilities affecting Nokogiri.
- CVE-2026-79772Nokogiri before 1.19.1 Unchecked Return Value canonicalize5.3
- CVE-2026-79770Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer7.5
- CVE-2026-79771Nokogiri before 1.19.3 Memory Leak via XSLT Transform5.3
- CVE-2026-79769Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args5.5
- CVE-2026-57438Nokogiri: Possible Use-After-Free in XInclude Processing6.6
- CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime5.3
- CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type5.3
- CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`7.5
- CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes7.5
- CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`8.2
- CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-262472.6
- CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception8.2
- GHSA-phwj-rprq-35ppNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`—
- GHSA-wfpw-mmfh-qq69Nokogiri: Possible Use-After-Free in XInclude Processing—
- GHSA-p67v-3w7g-wjg7Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime—
Product grouping is registry-driven, with AI assist and human review. How it works