CVE-2024-58378 PUBLISHED

Nokogiri before 1.16.2 Use-After-Free via xmlTextReader

Assigner: VulnCheck
Reserved: 16.08.2026 Published: 25.08.2026 Updated: 25.08.2026

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor sparklemotion
Product nokogiri
Versions Default: unaffected
  • affected from 1.16.0 to 1.16.2 (excl.)
  • Version 1.16.2 is unaffected
Vendor sparklemotion
Product nokogiri
Versions Default: unaffected
  • affected from 0 to 1.15.6 (excl.)
  • Version 1.15.6 is unaffected

References

Problem Types

  • Use After Free CWE