Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57438

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each xi:include in place, freeing the include node along with its children (such as xi:fallback and its descendants) and any namespaces declared on them. If an application had already exposed one of those nodes or namespaces to Ruby, the corresponding Ruby object was left pointing at freed memory. Using the object could result in invalid reads or writes to memory. This vulnerability is fixed in 1.19.4.

A flaw was found in Nokogiri, an XML and HTML library for the Ruby programming language. When performing XInclude substitutions, the library prematurely frees memory associated with nodes and namespaces. If an application has exposed these freed objects to Ruby, a local attacker could potentially trigger invalid reads or writes to memory. This memory corruption could lead to information disclosure or denial of service.

Отчет

A flaw was found in Nokogiri, an XML and HTML library for the Ruby programming language. When performing XInclude substitution via Nokogiri::XML::Node#do_xinclude, the library frees memory associated with replaced xi:include nodes, their children (including xi:fallback), and declared namespaces. If an application has already exposed one of these nodes or namespaces to Ruby, the corresponding Ruby object points to freed memory, which could result in invalid memory reads or writes. Red Hat products ship Nokogiri as a dependency of several components. The impact on Red Hat products is rated Moderate because exploitation requires the application to both perform XInclude substitution and separately retain references to nodes or namespaces within the substituted elements — a combination that is uncommon in typical usage patterns. This vulnerability only affects CRuby; JRuby is not affected. This issue is fixed in Nokogiri version 1.19.4.

Меры по смягчению последствий

Upgrade to Nokogiri 1.19.4 or later. As a workaround for earlier versions, perform XInclude substitution at parse time (with the xinclude parse option) rather than calling #do_xinclude on a document that has already been traversed. A freshly parsed document has no nodes exposed to Ruby, so the substitution is safe.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/backendFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/zyncFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/backendFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/zyncFix deferred
Red Hat 3scale API Management Platform 23scale-amp26/toolboxFix deferred
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2492963nokogiri: rubygem-nokogiri: Nokogiri: Memory corruption due to XInclude substitution

EPSS

Процентиль: 1%
0.00094
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in place, freeing the include node along with its children (such as <xi:fallback> and its descendants) and any namespaces declared on them. If an application had already exposed one of those nodes or namespaces to Ruby, the corresponding Ruby object was left pointing at freed memory. Using the object could result in invalid reads or writes to memory. This vulnerability is fixed in 1.19.4.

CVSS3: 6.6
nvd
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in place, freeing the include node along with its children (such as <xi:fallback> and its descendants) and any namespaces declared on them. If an application had already exposed one of those nodes or namespaces to Ruby, the corresponding Ruby object was left pointing at freed memory. Using the object could result in invalid reads or writes to memory. This vulnerability is fixed in 1.19.4.

CVSS3: 6.6
msrc
около 1 месяца назад

Nokogiri: Possible Use-After-Free in XInclude Processing

CVSS3: 6.6
debian
около 1 месяца назад

Nokogiri is an open source XML and HTML library for the Ruby programmi ...

EPSS

Процентиль: 1%
0.00094
Низкий

6.2 Medium

CVSS3