Junglewise Threat Intelligence

Nokogiri use-after-free in Document encoding assignment

Severity: low · CVSS 1.7 · Published 2026-06-19

Technologies: nokogiri (RubyGems). Vendors: RubyGems.

Executive brief

Nokogiri is a popular Ruby library used for processing XML and HTML data. A flaw in how it handles document encoding settings could allow an attacker to cause a program crash or potentially leak small amounts of memory. This occurs only in specific scenarios where an application attempts to set an invalid encoding and then continues to use the same document after an error occurs.

Technical details

A use-after-free vulnerability exists in the CRuby (libxml2) implementation of Nokogiri when setting `Document#encoding=`. If an invalid encoding (such as a non-string or a string containing a null byte) is provided, the library frees the current encoding string but raises an exception before assigning a new one. This leaves the document object with a dangling pointer to freed memory. Subsequent calls to `Document#encoding` may result in a segmentation fault or the leakage of freed memory into a Ruby string. This issue is fixed in version 1.19.4.

Affected products

  • sparklemotion Nokogiri < 1.19.4

Timeline

  • 2026-06-18: disclosed
  • 2026-06-19: advisory
  • 2026-06-19: patched

References

Related threats