Executive brief
Nokogiri is a popular XML/HTML parsing library used in Ruby applications. A type confusion bug in an internal copy helper method can cause a memory read error and crash the process when called with an incorrect argument type. This vulnerability requires application code to make a programming error (calling a protected internal method with a wrong type), and cannot be exploited through untrusted input or normal API use.
Technical details
This is a type confusion vulnerability (CWE-843) in the protected Node#initialize_copy_with_args helper method, which backs the public Node#dup and #clone methods. The vulnerable code unwraps the source argument as an xmlNode pointer without validating the argument type first. When a non-Node object (such as a Namespace) is passed, the code reads from an incompatible memory structure (xmlNs), resulting in an out-of-bounds read that crashes the process. Only CRuby is affected; JRuby is not impacted. The vulnerability is only reachable via intentional programmer error calling the protected internal method directly, not through untrusted input or normal public API usage. Nokogiri 1.19.4 fixes this by adding a type check that raises TypeError for invalid argument types.
Affected products
- Nokogiri Nokogiri before 1.19.4
Timeline
- 2026-06-18: disclosed: GitHub Security Advisory GHSA-g9g8-vgvw-g3vf published
- 2026-08-25: advisory: CVE-2026-79769 assigned and published on NVD
- 2026: patched: Fix available in Nokogiri 1.19.4