Ruby/nokogiri/1.18.6
Nokogiri (鋸) makes it easy and painless to work with XML and HTML from Ruby. It provides a sensible, easy-to-understand API for reading, writing, modifying, and querying documents. It is fast and standards-compliant by relying on native parsers like libxml2, libgumbo, or xerces.
https://rubygems.org/gems/nokogiri
MIT
1 Security Vulnerabilities
Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415
Summary
Nokogiri v1.18.8 upgrades its dependency libxml2 to v2.13.8.
libxml2 v2.13.8 addresses:
- CVE-2025-32414
- described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/889
- CVE-2025-32415
- described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/890
Impact
CVE-2025-32414: No impact
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
There is no impact from this CVE for Nokogiri users.
CVE-2025-32415: Low impact
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
In the upstream issue, further context is provided by the maintainer:
The bug affects validation against untrusted XML Schemas (.xsd) and validation of untrusted documents against trusted Schemas if they make use of xsd:keyref in combination with recursively defined types that have additional identity constraints.
MITRE has published a severity score of 2.9 LOW (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) for this CVE.
188 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
1.6.7 | MIT | 72 | 2015-11-30 - 04:21 | over 9 years |
1.6.7.rc4 | MIT | 72 | 2015-11-22 - 22:56 | over 9 years |
1.6.7.rc3 | MIT | 73 | 2015-09-04 - 17:34 | almost 10 years |
1.6.7.rc2 | MIT | 73 | 2015-08-31 - 13:51 | almost 10 years |
1.6.6.4 | MIT | 72 | 2015-11-19 - 20:58 | over 9 years |
1.6.6.3 | MIT | 73 | 2015-11-17 - 00:02 | over 9 years |
1.6.6.2 | MIT | 73 | 2015-01-23 - 18:53 | over 10 years |
1.6.6.1 | MIT | 73 | 2015-01-22 - 18:42 | over 10 years |
1.6.5 | MIT | 73 | 2014-11-26 - 21:07 | over 10 years |
1.6.4.1 | MIT | 73 | 2014-11-07 - 03:03 | over 10 years |
1.6.4 | MIT | 73 | 2014-11-05 - 04:32 | over 10 years |
1.6.3.1 | MIT | 73 | 2014-07-22 - 01:35 | almost 11 years |
1.6.3 | MIT | 73 | 2014-07-20 - 18:57 | almost 11 years |
1.6.3.rc3 | MIT | 74 | 2014-06-21 - 20:31 | about 11 years |
1.6.3.rc2 | MIT | 74 | 2014-06-17 - 17:04 | about 11 years |
1.6.3.rc1 | MIT | 74 | 2014-05-22 - 19:23 | about 11 years |
1.6.2.1 | MIT | 73 | 2014-05-14 - 01:21 | about 11 years |
1.6.2 | MIT | 74 | 2014-05-12 - 22:31 | about 11 years |
1.6.2.rc3 | MIT | 73 | 2014-05-09 - 22:00 | about 11 years |
1.6.2.rc2 | MIT | 73 | 2014-04-10 - 17:15 | about 11 years |
1.6.2.rc1 | MIT | 73 | 2014-04-06 - 20:37 | about 11 years |
1.6.1 | MIT | 74 | 2013-12-15 - 01:54 | over 11 years |
1.6.0 | UNKNOWN | 78 | 2013-06-10 - 14:38 | about 12 years |
1.6.0.rc1 | UNKNOWN | 70 | 2013-04-23 - 17:32 | about 12 years |
1.5.11 | MIT | 68 | 2013-12-15 - 01:53 | over 11 years |
1.5.10 | UNKNOWN | 70 | 2013-06-07 - 21:16 | about 12 years |
1.5.9 | UNKNOWN | 70 | 2013-03-21 - 13:35 | over 12 years |
1.5.8 | UNKNOWN | 70 | 2013-03-19 - 19:56 | over 12 years |
1.5.7 | UNKNOWN | 70 | 2013-03-18 - 20:10 | over 12 years |
1.5.7.rc3 | UNKNOWN | 70 | 2013-03-14 - 12:50 | over 12 years |
1.5.7.rc2 | UNKNOWN | 70 | 2013-03-11 - 09:46 | over 12 years |
1.5.7.rc1 | UNKNOWN | 70 | 2013-02-22 - 18:36 | over 12 years |
1.5.6 | UNKNOWN | 70 | 2012-12-19 - 16:41 | over 12 years |
1.5.6.rc3 | UNKNOWN | 70 | 2012-11-27 - 00:36 | over 12 years |
1.5.6.rc2 | UNKNOWN | 70 | 2012-09-12 - 15:53 | almost 13 years |
1.5.6.rc1 | UNKNOWN | 70 | 2012-07-11 - 18:06 | almost 13 years |
1.5.5 | UNKNOWN | 70 | 2012-06-23 - 16:21 | about 13 years |
1.5.5.rc3 | UNKNOWN | 70 | 2012-06-22 - 15:22 | about 13 years |
1.5.5.rc2 | UNKNOWN | 70 | 2012-06-14 - 16:35 | about 13 years |
1.5.5.rc1 | UNKNOWN | 70 | 2012-06-12 - 14:04 | about 13 years |
1.5.4 | UNKNOWN | 70 | 2012-06-11 - 15:09 | about 13 years |
1.5.4.rc3 | UNKNOWN | 72 | 2012-06-08 - 18:58 | about 13 years |
1.5.4.rc2 | UNKNOWN | 72 | 2012-06-08 - 15:26 | about 13 years |
1.5.4.rc1 | UNKNOWN | 72 | 2012-06-07 - 20:34 | about 13 years |
1.5.3 | UNKNOWN | 72 | 2012-06-01 - 13:53 | about 13 years |
1.5.3.rc6 | UNKNOWN | 72 | 2012-05-30 - 15:25 | about 13 years |
1.5.3.rc5 | UNKNOWN | 72 | 2012-04-27 - 14:55 | about 13 years |
1.5.3.rc4 | UNKNOWN | 72 | 2012-04-27 - 04:11 | about 13 years |
1.5.3.rc3 | UNKNOWN | 72 | 2012-03-26 - 22:07 | over 13 years |
1.5.3.rc2 | UNKNOWN | 72 | 2012-03-22 - 15:29 | over 13 years |