Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sparklemotion
Sparklemotion nokogiri |
|
| Vendors & Products |
Sparklemotion
Sparklemotion nokogiri |
Tue, 25 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity. | |
| Title | Nokogiri before 1.18.8 Heap Buffer Under-read via XML Schema | |
| First Time appeared |
Nokogiri
Nokogiri nokogiri |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokogiri
Nokogiri nokogiri |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T16:16:01.093Z
Reserved: 2026-06-20T12:48:06.735Z
Link: CVE-2025-71346
Updated: 2026-08-25T16:15:53.135Z
Status : Received
Published: 2026-08-25T16:16:45.320
Modified: 2026-08-25T17:17:04.740
Link: CVE-2025-71346
No data.
OpenCVE Enrichment
Updated: 2026-08-25T17:30:07Z
-
CWE-125
Out-of-bounds Read