Executive brief
Nokogiri is a widely used Ruby library for processing XML and HTML data. A technical flaw in how the library handles document structures could allow a programming error to crash the application or cause unpredictable behavior. This issue primarily affects the stability of the service and is resolved by updating to the latest version of the library.
Technical details
A use-after-free vulnerability exists in the CRuby implementation of Nokogiri (libxml2) within the `Nokogiri::XML::Document#root=` method. The component failed to properly restrict the type of node being assigned as the document root, allowing non-element nodes such as DTD nodes to be set. This leads to a heap use-after-free condition during garbage collection or finalization, potentially causing an invalid memory read or a segmentation fault. The vulnerability is triggered by specific application code patterns rather than direct untrusted input. It is fixed in version 1.19.4, which now enforces that only element nodes can be assigned as roots.
Affected products
- sparklemotion Nokogiri < 1.19.4
Timeline
- 2026-06-18: advisory: GitHub Security Advisory published
- 2026-06-25: disclosed: CVE published to NVD