CVE-2025-71406
Severity CVSS v4.0:
HIGH
Type:
CWE-416
Use After Free
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking xpathCtxt->node) and CVE-2024-55549 (use-after-free related to excluded result prefixes/namespaces). Processing crafted XSLT can trigger memory corruption. Nokogiri 1.18.4 upgrades the bundled libxslt to 1.1.43 to resolve these issues.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH



