CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-58378

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-25
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.

⚡ Watch CVE-2024-58378

Get an email if CVE-2024-58378 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2024-58378

CVE.org record

Embed the live status

CVE-2024-58378 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2024-58378 status](https://www.csirts.com/badge/CVE-2024-58378)](https://www.csirts.com/cve/CVE-2024-58378)