Executive brief
A security issue was found in Nokogiri, a popular tool used by developers to process XML and HTML data. On JRuby systems, a safety feature designed to block unauthorized network requests was not working correctly. This could allow a malicious file to trick the system into making unexpected network connections, potentially leading to the exposure of internal information.
Technical details
A vulnerability exists in the JRuby implementation of Nokogiri where the NONET parse option is not correctly enforced for XML::Schema. While Nokogiri enables NONET by default to prevent external entity loading, the JRuby version failed to block network schemes, whereas the CRuby version (using libxml2) correctly blocks them at the I/O layer. This flaw allows an attacker to bypass previous security fixes (CVE-2020-26247) and perform Server-Side Request Forgery (SSRF) or XML External Entity (XXE) attacks. The issue is resolved in version 1.19.4 by replacing the previous scheme denylist with a strict allowlist that only permits local file resources when NONET is active.
Affected products
- sparklemotion Nokogiri < 1.19.4
Timeline
- 2026-06-18: disclosed
- 2026-06-19: advisory
- 2026-06-19: patched: Fixed in version 1.19.4