Executive brief
Nokogiri is a widely used Ruby library for processing XML and HTML documents. A technical flaw in how the library manages memory could cause an application to crash (segmentation fault) if it uses a specific, advanced programming pattern. This issue does not affect standard document searching and cannot be triggered by malicious user input alone; it requires a specific sequence of events in the application's own code.
Technical details
A Use-After-Free (CWE-416) vulnerability exists in the CRuby implementation of Nokogiri. The `Nokogiri::XML::XPathContext` class failed to maintain a reference to its parent XML document, allowing the Ruby garbage collector to reclaim the document's memory while the context was still in use. If an application manually constructs an `XPathContext` and the source document is collected, subsequent XPath evaluations will read invalid memory, leading to a segmentation fault. This is not triggerable via malicious XML input and does not affect the high-level `Document#xpath` or `#css` methods. The issue is resolved in version 1.19.4 by ensuring the context keeps the source document alive.
Affected products
- sparklemotion Nokogiri < 1.19.4
Timeline
- 2026-06-18: advisory: GitHub advisory published by maintainers
- 2026-06-25: disclosed: CVE published to NVD