CVE Explorer
CVE-2026-57438
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in place, freeing the include node along with its children (such as <xi:fallback> and its descendants) and any namespaces declared on them. If an application had already exposed one of those nodes or namespaces to Ruby, the corresponding Ruby object was left pointing at freed memory. Using the object coul
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nokogiri","vendor":"sparklemotion","versions":[{"status":"affected","version":"< 1.19.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c398a6c6731d8729f1871cb785df11be1b91256a4cecde175469a54e82ae35c0 · sha256:5f3bfea9e4ed854f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":2.2,"baseSeverity":"LOW","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c398a6c6731d8729f1871cb785df11be1b91256a4cecde175469a54e82ae35c0 · sha256:5f3bfea9e4ed854f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c398a6c6731d8729f1871cb785df11be1b91256a4cecde175469a54e82ae35c0 · sha256:5f3bfea9e4ed854f… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wfpw-mmfh-qq69","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wfpw-mmfh-qq69"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c398a6c6731d8729f1871cb785df11be1b91256a4cecde175469a54e82ae35c0 · sha256:5f3bfea9e4ed854f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.