VDB
KO

package

RubyGems / nokogiri

pkg:rubygems/nokogiri

MEDIUM RubyGems
GHSA-2qc6-mcvw-92cw

Update bundled libxml2 to v2.10.3 to resolve multiple CVEs

Modified: 12/2/2024

CRITICAL RubyGems
GHSA-353f-x4gh-cqq8

Nokogiri patches vendored libxml2 to resolve multiple CVEs

Modified: 2/4/2026

LOW RubyGems
GHSA-5w6v-399v-w3cc

Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415

Modified: 2/4/2026

MEDIUM RubyGems
GHSA-7rrm-v45f-jp64

Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12

Modified: 11/30/2024

HIGH 7.5 RubyGems
GHSA-c4rq-3m3g-8wgx

Nokogiri CSS selector tokenizer has regular expression backtracking

Modified: 5/9/2026

HIGH 8.6 RubyGems
GHSA-cgx6-hpwq-fhv5

Integer Overflow or Wraparound in libxml2 affects Nokogiri

Modified: 12/7/2024

HIGH 7.8 RubyGems
GHSA-mrxw-mxhj-p664

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

Modified: 2/4/2026

MEDIUM RubyGems
GHSA-pxvg-2qj5-37jq

Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs

Modified: 12/4/2024

LOW RubyGems
GHSA-r95h-9x8f-r3f7

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

Modified: 2/4/2026

LOW RubyGems
GHSA-vvfq-8hwr-qm4m

Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171

Modified: 2/4/2026

MEDIUM 5.3 RubyGems
GHSA-wx95-c6cv-8532

Nokogiri does not check the return value from xmlC14NExecute

Modified: 2/25/2026

MEDIUM RubyGems
GHSA-xc9x-jj77-9p9j

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

Modified: 2/4/2026

MEDIUM 6.5 RubyGems
GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

Modified: 12/5/2024