Loading...
Skip to main content
RubyGems (Ruby)

nokogiri Security Analysis

nokogiri has 33 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 1.19.4 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

33 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 1.19.4

Upgrading to 1.19.4 or later resolves all 33 known vulnerabilities in nokogiri. Run: gem install nokogiri -v 1.19.4

Is nokogiri in your project?

Check if you're affected and upgrade to 1.19.4 to stay secure.

33
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

33 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2019-11068
Nokogiri vulnerable to libxslt protection mechanism bypass
CRITICAL
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+108 more)1.10.3
CVE-2019-5477
Nokogiri Command Injection Vulnerability
CRITICAL
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+109 more)1.10.4
CVE-2016-4658
Nokogiri does not forbid namespace nodes in XPointer ranges
CRITICAL
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+93 more)1.7.1
CVE-2021-30560
Nokogiri has vulnerable dependencies on libxml2 and libxslt
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+137 more)1.13.2
CVE-2021-3518
Nokogiri Implements libxml2 version vulnerable to use-after-free
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more)1.11.4
CVE-2017-15412
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+97 more)1.8.2
CVE-2021-3517
Nokogiri contains libxml Out-of-bounds Write vulnerability
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more)1.11.4
CVE-2017-5029
Nokogiri implementation of libxslt lacks integer overflow checks
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+94 more)1.7.2
CVE-2022-29181
Nokogiri Improperly Handles Unexpected Data Type
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+141 more)1.13.6
CVE-2022-23476
Unchecked return value from xmlTextReaderExpand
HIGH
1.13.8, 1.13.91.13.10
CVE-2019-5815
Nokogiri implementation of libxslt vulnerable to heap corruption
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more)1.10.5
CVE-2019-18197
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more)1.10.5
CVE-2019-13118
libxslt Type Confusion vulnerability that affects Nokogiri
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more)1.10.5
CVE-2017-16932
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+96 more)1.8.1
CVE-2012-6685
Nokogiri is vulnerable to XML External Entity (XXE) attack
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+43 more)1.5.4
CVE-2022-24836
Nokogiri Inefficient Regular Expression Complexity
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+139 more)1.13.4
CVE-2018-25032
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+139 more)1.13.4
CVE-2021-41098
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+134 more)1.12.5
CVE-2020-7595
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+113 more)1.10.8
CVE-2015-8806
Denial of service or RCE from libxml2 and libxslt
HIGH
1.6.0, 1.6.1, 1.6.2, 1.6.2.1 (+24 more)1.6.8
GHSA-c4rq-3m3g-8wgx
Nokogiri CSS selector tokenizer has regular expression backtracking
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+189 more)1.19.3
GHSA-mrxw-mxhj-p664
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+179 more)1.18.4
GHSA-cgx6-hpwq-fhv5
Integer Overflow or Wraparound in libxml2 affects Nokogiri
HIGH
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+140 more)1.13.5
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
MEDIUM
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4
CVE-2013-6460
Nokogiri vulnerable to DoS while parsing XML documents
MEDIUM
1.5.0, 1.5.1, 1.5.1.rc1, 1.5.10 (+26 more)1.5.11, 1.6.1
CVE-2013-6461
Nokogiri vulnerable to DoS while parsing XML entities
MEDIUM
1.5.0, 1.5.1, 1.5.1.rc1, 1.5.10 (+26 more)1.5.11, 1.6.1
CVE-2017-18258
Uncontrolled resource consumption in nokogiri
MEDIUM
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+97 more)1.8.2
CVE-2021-3537
Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
MEDIUM
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more)1.11.4
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
LOW
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
LOW
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4
CVE-2026-57436
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
LOW
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4
CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
LOW
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4
CVE-2026-57236
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
LOW
1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more)1.19.4

About This Data

Vulnerability data for nokogiri is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related RubyGems (Ruby) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of nokogiri.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed