Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.
CVSS Details
- CVSS 3.1 Base Score: 2.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-nokogiri | Aug 22, 2024 | Dec 30, 2020 |
| Debian | — | Upgrade ruby-nokogiri | Jun 8, 2021 | Dec 30, 2020 |
| Freebsd | — | Upgrade rubygem-nokogiriUpgrade rubygem-nokogiri18 | Jan 22, 2021 | Jan 22, 2021 |
| Gentoo Linux | — | Upgrade dev-ruby/nokogiri. | Aug 16, 2022 | Dec 30, 2020 |
| Suse | — | Upgrade ruby2.5-rubygem-nokogiri-testsuiteUpgrade ruby2.5-rubygem-nokogiri-docUpgrade ruby2.5-rubygem-nokogiri | Feb 6, 2021 | Dec 30, 2020 |
| Ubuntu | — | Upgrade ruby-nokogiri (Ubuntu Pro) | Jun 26, 2025 | Dec 30, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub