CVE-2021-47996
Severity CVSS v4.0:
HIGH
Type:
CWE-119
Buffer Errors
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/sparklemotion/nokogiri/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5
- https://github.com/sparklemotion/nokogiri/commit/1098c30a040e72a4654968547f415be4e4c40fe7
- https://github.com/sparklemotion/nokogiri/commit/1358d157d0bd83be1dfe356a69213df9fac0b539
- https://github.com/sparklemotion/nokogiri/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2
- https://github.com/sparklemotion/nokogiri/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a
- https://github.com/sparklemotion/nokogiri/commit/8598060bacada41a0eb09d95c97744ff4e428f8e
- https://github.com/sparklemotion/nokogiri/commit/babe75030c7f64a37826bb3342317134568bef61
- https://github.com/sparklemotion/nokogiri/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64
- https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-via-libxml2



