CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-71407

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-25
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.

⚡ Watch CVE-2025-71407

Get an email if CVE-2025-71407 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2025-71407

CVE.org record

Embed the live status

CVE-2025-71407 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-71407 status](https://www.csirts.com/badge/CVE-2025-71407)](https://www.csirts.com/cve/CVE-2025-71407)