THREAT OPS › Threat News › [NVD] CVE-2024-58378 (CRITICAL 9.8) — Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD vali
[NVD] CVE-2024-58378 (CRITICAL 9.8) — Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD vali
CVE-2024-58378 CVSS: 9.8 CRITICAL Published: 2026-08-25T16:16:45.153
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing
Indicators of compromise
- CVE-2024-58378cve
- CVE-2024-25062cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-58378