CVE Tools

Nokogiri

71 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nokogiri, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Nokogiri CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nokogiri CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-031
2025-041
2025-050
2025-062
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-052
2026-0616
2026-070
2026-084
2026-090

Severity

How the 71 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High2350%
  • Medium1635%
  • Low49%

Latest CVEs

The 15 most recently published vulnerabilities affecting Nokogiri.

  1. CVE-2026-79772Nokogiri before 1.19.1 Unchecked Return Value canonicalize5.3
  2. CVE-2026-79770Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer7.5
  3. CVE-2026-79771Nokogiri before 1.19.3 Memory Leak via XSLT Transform5.3
  4. CVE-2026-79769Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args5.5
  5. CVE-2026-57438Nokogiri: Possible Use-After-Free in XInclude Processing6.6
  6. CVE-2026-57437Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime5.3
  7. CVE-2026-57436Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type5.3
  8. CVE-2026-57435Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`7.5
  9. CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes7.5
  10. CVE-2026-57235Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`8.2
  11. CVE-2026-57234Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-262472.6
  12. CVE-2026-57236Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception8.2
  13. GHSA-phwj-rprq-35ppNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`—
  14. GHSA-wfpw-mmfh-qq69Nokogiri: Possible Use-After-Free in XInclude Processing—
  15. GHSA-p67v-3w7g-wjg7Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store