CVE-2025-71346
Severity CVSS v4.0:
HIGH
Type:
CWE-125
Out-of-bounds Read
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
2.90
Severity 3.x
LOW



