Junglewise Threat Intelligence

CVE-2026-57437: Nokogiri use-after-free in XML::XPathContext

CVE-2026-57437 · Severity: medium · CVSS 4 · Published 2026-06-25

Technologies: nokogiri (RubyGems). Vendors: RubyGems.

Executive brief

Nokogiri is a widely used Ruby library for processing XML and HTML documents. A technical flaw in how the library manages memory could cause an application to crash (segmentation fault) if it uses a specific, advanced programming pattern. This issue does not affect standard document searching and cannot be triggered by malicious user input alone; it requires a specific sequence of events in the application's own code.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in the CRuby implementation of Nokogiri. The `Nokogiri::XML::XPathContext` class failed to maintain a reference to its parent XML document, allowing the Ruby garbage collector to reclaim the document's memory while the context was still in use. If an application manually constructs an `XPathContext` and the source document is collected, subsequent XPath evaluations will read invalid memory, leading to a segmentation fault. This is not triggerable via malicious XML input and does not affect the high-level `Document#xpath` or `#css` methods. The issue is resolved in version 1.19.4 by ensuring the context keeps the source document alive.

Affected products

  • sparklemotion Nokogiri < 1.19.4

Timeline

  • 2026-06-18: advisory: GitHub advisory published by maintainers
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats