CRITICAL 9.3 NVD

CVE-2024-58377

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxm

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not provide or expose the xmllint tool where the issue occurs.

References

Published: 2026-08-25 · Source: NVD · Feed updated: 2026-08-25
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-25 via NVD.

Risk Timeline

CVE Disclosed2026-08-25 · -1 days ago

Remediation Resources

vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.