This CVE ID has been rejected as a duplicate.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade Nokogiri to version 1.15.6 or 1.16.2, which incorporate the updated libxml2 packages that fix the use‑after‑free.
- If upgrading immediately is not possible, disable DTD validation and XInclude expansion in all uses of Nokogiri::XML::Reader to mitigate the trigger for the memory corruption.
- Ensure the deployment environment uses the packaged libxml2 supplied with Nokogiri and that it is at least 2.11.7 for 1.15.x or 2.12.5 for 1.16.x, or switch to a system libxml2 that is not affected by the underlying CVE‑2024‑25062 flaw.
Generated by OpenCVE AI on August 25, 2026 at 16:21 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | rubygem-nokogiri: Nokogiri before 1.16.2 Use-After-Free via xmlTextReader | |
| Weaknesses | CWE-416 | |
| References |
|
|
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected. | This CVE ID has been rejected as a duplicate. |
| Title | Nokogiri before 1.16.2 Use-After-Free via xmlTextReader | |
| Weaknesses | CWE-416 | |
| CPEs | ||
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 25 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sparklemotion
Sparklemotion nokogiri |
|
| Vendors & Products |
Sparklemotion
Sparklemotion nokogiri |
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected. | |
| Title | Nokogiri before 1.16.2 Use-After-Free via xmlTextReader | |
| First Time appeared |
Nokogiri
Nokogiri nokogiri |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokogiri
Nokogiri nokogiri |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T20:33:43.529Z
Reserved: 2026-08-16T13:02:14.690Z
Link: CVE-2024-58378
Updated:
Status : Rejected
Published: 2026-08-25T16:16:45.153
Modified: 2026-09-01T21:17:42.907
Link: CVE-2024-58378
OpenCVE Enrichment
Updated: 2026-08-25T19:00:07Z
-
CWE-416
Use After Free