Search CVE reports


Toggle filters

11 – 20 of 23 results


CVE-2026-57235

Medium priority
Needs evaluation

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's bounds using...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-57234

Medium priority
Needs evaluation

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-6494

Medium priority
Not affected

A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-parser/src/hashmap.c. The...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-6490

Medium priority
Not affected

A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-23476

Medium priority
Ignored

Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-29181

Medium priority

Some fixes available 2 of 6

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2022-24836

Medium priority
Vulnerable

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2021-41098

Medium priority
Not affected

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected
Show less packages

CVE-2020-26247

Medium priority

Some fixes available 1 of 7

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted...

1 affected package

ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-nokogiri Not affected Not affected Fixed Not affected
Show less packages

CVE-2012-6685

Medium priority
Ignored

Nokogiri before 1.5.4 is vulnerable to XXE attacks

2 affected packages

libnokogiri-ruby, ruby-nokogiri

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnokogiri-ruby
ruby-nokogiri
Show less packages