CVE-2026-57434EPSS p28.6%
CVE-2026-57434CVE-2026-57434
nokogiri / nokogiri
Description
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.36% probability of exploitation · percentile 28.6% · 2026-08-11T12:00:17Z |
| Last modified | 2026-06-26 |