nokogiri Security Analysis
nokogiri has 33 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 1.19.4 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 1.19.4
Upgrading to 1.19.4 or later resolves all 33 known vulnerabilities in nokogiri. Run: gem install nokogiri -v 1.19.4
Is nokogiri in your project?
Check if you're affected and upgrade to 1.19.4 to stay secure.
Vulnerabilities
33 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2019-11068 Nokogiri vulnerable to libxslt protection mechanism bypass | CRITICAL | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+108 more) | 1.10.3 |
| CVE-2019-5477 Nokogiri Command Injection Vulnerability | CRITICAL | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+109 more) | 1.10.4 |
| CVE-2016-4658 Nokogiri does not forbid namespace nodes in XPointer ranges | CRITICAL | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+93 more) | 1.7.1 |
| CVE-2021-30560 Nokogiri has vulnerable dependencies on libxml2 and libxslt | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+137 more) | 1.13.2 |
| CVE-2021-3518 Nokogiri Implements libxml2 version vulnerable to use-after-free | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more) | 1.11.4 |
| CVE-2017-15412 Nokogiri gem, via libxml, is affected by DoS vulnerabilities | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+97 more) | 1.8.2 |
| CVE-2021-3517 Nokogiri contains libxml Out-of-bounds Write vulnerability | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more) | 1.11.4 |
| CVE-2017-5029 Nokogiri implementation of libxslt lacks integer overflow checks | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+94 more) | 1.7.2 |
| CVE-2022-29181 Nokogiri Improperly Handles Unexpected Data Type | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+141 more) | 1.13.6 |
| CVE-2022-23476 Unchecked return value from xmlTextReaderExpand | HIGH | 1.13.8, 1.13.9 | 1.13.10 |
| CVE-2019-5815 Nokogiri implementation of libxslt vulnerable to heap corruption | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more) | 1.10.5 |
| CVE-2019-18197 Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more) | 1.10.5 |
| CVE-2019-13118 libxslt Type Confusion vulnerability that affects Nokogiri | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+110 more) | 1.10.5 |
| CVE-2017-16932 Nokogiri gem, via libxml, is affected by DoS vulnerabilities | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+96 more) | 1.8.1 |
| CVE-2012-6685 Nokogiri is vulnerable to XML External Entity (XXE) attack | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+43 more) | 1.5.4 |
| CVE-2022-24836 Nokogiri Inefficient Regular Expression Complexity | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+139 more) | 1.13.4 |
| CVE-2018-25032 Nokogiri affected by zlib's Out-of-bounds Write vulnerability | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+139 more) | 1.13.4 |
| CVE-2021-41098 Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+134 more) | 1.12.5 |
| CVE-2020-7595 libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+113 more) | 1.10.8 |
| CVE-2015-8806 Denial of service or RCE from libxml2 and libxslt | HIGH | 1.6.0, 1.6.1, 1.6.2, 1.6.2.1 (+24 more) | 1.6.8 |
| GHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtracking | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+189 more) | 1.19.3 |
| GHSA-mrxw-mxhj-p664 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+179 more) | 1.18.4 |
| GHSA-cgx6-hpwq-fhv5 Integer Overflow or Wraparound in libxml2 affects Nokogiri | HIGH | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+140 more) | 1.13.5 |
| CVE-2026-57235 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | MEDIUM | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
| CVE-2013-6460 Nokogiri vulnerable to DoS while parsing XML documents | MEDIUM | 1.5.0, 1.5.1, 1.5.1.rc1, 1.5.10 (+26 more) | 1.5.11, 1.6.1 |
| CVE-2013-6461 Nokogiri vulnerable to DoS while parsing XML entities | MEDIUM | 1.5.0, 1.5.1, 1.5.1.rc1, 1.5.10 (+26 more) | 1.5.11, 1.6.1 |
| CVE-2017-18258 Uncontrolled resource consumption in nokogiri | MEDIUM | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+97 more) | 1.8.2 |
| CVE-2021-3537 Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing | MEDIUM | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+124 more) | 1.11.4 |
| CVE-2026-57435 Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` | LOW | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
| CVE-2026-57437 Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime | LOW | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
| CVE-2026-57436 Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type | LOW | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
| CVE-2026-57434 Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes | LOW | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
| CVE-2026-57236 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception | LOW | 1.0.0, 1.0.1, 1.0.2, 1.0.3 (+190 more) | 1.19.4 |
About This Data
Vulnerability data for nokogiri is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related RubyGems (Ruby) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of nokogiri.