Junglewise Threat Intelligence

Nokogiri XML::Schema NONET bypass in JRuby

Severity: low · CVSS 2.6 · Published 2026-06-19

Technologies: nokogiri (RubyGems). Vendors: RubyGems.

Executive brief

A security issue was found in Nokogiri, a popular tool used by developers to process XML and HTML data. On JRuby systems, a safety feature designed to block unauthorized network requests was not working correctly. This could allow a malicious file to trick the system into making unexpected network connections, potentially leading to the exposure of internal information.

Technical details

A vulnerability exists in the JRuby implementation of Nokogiri where the NONET parse option is not correctly enforced for XML::Schema. While Nokogiri enables NONET by default to prevent external entity loading, the JRuby version failed to block network schemes, whereas the CRuby version (using libxml2) correctly blocks them at the I/O layer. This flaw allows an attacker to bypass previous security fixes (CVE-2020-26247) and perform Server-Side Request Forgery (SSRF) or XML External Entity (XXE) attacks. The issue is resolved in version 1.19.4 by replacing the previous scheme denylist with a strict allowlist that only permits local file resources when NONET is active.

Affected products

  • sparklemotion Nokogiri < 1.19.4

Timeline

  • 2026-06-18: disclosed
  • 2026-06-19: advisory
  • 2026-06-19: patched: Fixed in version 1.19.4

References

Related threats