top of page
perceptive_background_267k.jpg

Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-fre…

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 19:07:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

Nokogiri versions prior to 1.18.4 bundle a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities. CVE-2025-24855 involves a use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking xpathCtxt->node. CVE-2024-55549 involves a use-after-free related to excluded result prefixes and namespaces. Processing specially crafted XSLT input can trigger memory corruption exploiting these flaws. The vulnerabilities are inherited through Nokogiri's bundled dependency on libxslt, representing a supply chain risk. Nokogiri 1.18.4 resolves both issues by upgrading the bundled libxslt to version 1.1.43. Users of Nokogiri are advised to upgrade to version 1.18.4 or later immediately.

Technical details

Mitigation steps:

Affected products:

Nokogiri
libxslt

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page