Nokogiri is a widely embedded XML and HTML parsing library for Ruby that despite its narrow product focus sits prominently in the software supply chain, with vulnerabilities propagating to every downstream application that depends on it. The recurring exposure centers on XML-processing weaknesses including entity-expansion denial of service, external entity references, and type-confusion conditions in parsing logic, alongside occasional OS command injection issues that reflect the library's role in untrusted document handling. Defenders should track Nokogiri advisories closely and prioritize remediation across dependent applications rather than the library in isolation, since a single flaw can affect a broad ecosystem; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nokogiri over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
CVE-2026-57235HIGH Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index aga | Jun 25, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-57236HIGH Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a st | Jun 25, 2026 | 8.2 | 33 | NO | NO |
CVE-2019-5477CRITICAL A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if t | Aug 16, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-57435HIGH Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed m | Jun 25, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-57434HIGH Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitiali | Jun 25, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-57438MEDIUM Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each | Jun 25, 2026 | 6.6 | 29 | NO | NO |
CVE-2026-57437MEDIUM Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage c | Jun 25, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-57436MEDIUM Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::X | Jun 25, 2026 | 5.3 | 26 | NO | NO |
CVE-2022-23476HIGH Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the m | Dec 8, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nokogiri.
Media articles that mention a CVE ID that affects a product developed by Nokogiri — matched by CVE ID, not by vendor name.