CVE-2024-58377 PUBLISHED

Nokogiri before 1.16.5 libxml2 Dependency Update

Assigner: VulnCheck
Reserved: 16.08.2026 Published: 25.08.2026 Updated: 25.08.2026

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not provide or expose the xmllint tool where the issue occurs.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor sparklemotion
Product nokogiri
Versions Default: unaffected
  • affected from 0 to 1.16.5 (excl.)
  • Version 1.16.5 is unaffected

References

Problem Types

  • Uncontrolled Search Path Element CWE