Executive brief
Nokogiri is a widely used Ruby library for processing XML and HTML data. A technical flaw in how the library handles memory when updating document attributes could lead to application crashes (segmentation faults). While this issue is unlikely to occur during standard use, it could impact the stability of applications that perform complex manipulations of XML data.
Technical details
A use-after-free (CWE-416) and expired pointer dereference (CWE-825) vulnerability exists in Nokogiri's CRuby native extension. When a Ruby wrapper for an attribute's child node is accessed and subsequently the attribute's value is replaced using `Nokogiri::XML::Attr#value=` or `#content=`, the underlying native memory for the child node is freed while the Ruby wrapper remains reachable. Subsequent access or Ruby Garbage Collection (GC) marking can dereference this invalid pointer, leading to an invalid read and a segmentation fault. This issue is specific to the CRuby implementation; JRuby is not affected. The vulnerability is addressed in version 1.19.4 by ensuring already-wrapped child nodes are preserved during value replacement.
Affected products
- sparklemotion nokogiri < 1.19.4
Timeline
- 2026-06-18: advisory: GitHub advisory published by maintainers
- 2026-06-25: disclosed: CVE published to NVD