Description
Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resulting in a denial of service. Nokogiri 1.14.3 upgrades the packaged libxml2 to v2.10.4 to resolve these issues.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resulting in a denial of service. Nokogiri 1.14.3 upgrades the packaged libxml2 to v2.10.4 to resolve these issues. | |
| Title | Nokogiri before 1.14.3 Null Pointer Dereference via libxml2 | |
| First Time appeared |
Nokogiri
Nokogiri nokogiri |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokogiri
Nokogiri nokogiri |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T16:12:06.863Z
Reserved: 2026-01-10T01:51:52.987Z
Link: CVE-2023-54354
No data.
Status : Received
Published: 2026-08-25T16:16:44.543
Modified: 2026-08-25T16:16:44.543
Link: CVE-2023-54354
No data.
OpenCVE Enrichment
Updated: 2026-08-25T16:30:05Z
Weaknesses
-
CWE-476
NULL Pointer Dereference