Description
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.
Published: 2026-08-25
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://github.com/GNOME/libxml2/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5 cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/1098c30a040e72a4654968547f415be4e4c40fe7 cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/1358d157d0bd83be1dfe356a69213df9fac0b539 cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2 cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/8598060bacada41a0eb09d95c97744ff4e428f8e cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/babe75030c7f64a37826bb3342317134568bef61 cve-icon cve-icon
https://github.com/GNOME/libxml2/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2 cve-icon cve-icon
https://github.com/sparklemotion/nokogiri/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5 cve-icon
https://github.com/sparklemotion/nokogiri/commit/1098c30a040e72a4654968547f415be4e4c40fe7 cve-icon
https://github.com/sparklemotion/nokogiri/commit/1358d157d0bd83be1dfe356a69213df9fac0b539 cve-icon
https://github.com/sparklemotion/nokogiri/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2 cve-icon
https://github.com/sparklemotion/nokogiri/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a cve-icon
https://github.com/sparklemotion/nokogiri/commit/8598060bacada41a0eb09d95c97744ff4e428f8e cve-icon
https://github.com/sparklemotion/nokogiri/commit/babe75030c7f64a37826bb3342317134568bef61 cve-icon
https://github.com/sparklemotion/nokogiri/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2 cve-icon
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2021-47996 cve-icon
https://www.cve.org/CVERecord?id=CVE-2021-47996 cve-icon
https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-via-libxml2 cve-icon cve-icon cve-icon
History

Fri, 28 Aug 2026 15:30:00 +0000


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

threat_severity

Important


Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Sparklemotion
Sparklemotion nokogiri
Vendors & Products Sparklemotion
Sparklemotion nokogiri

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.
Title Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2
First Time appeared Nokogiri
Nokogiri nokogiri
Weaknesses CWE-119
CPEs cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:*
Vendors & Products Nokogiri
Nokogiri nokogiri
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nokogiri Nokogiri
Sparklemotion Nokogiri
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T15:18:20.801Z

Reserved: 2026-08-25T14:31:58.552Z

Link: CVE-2021-47996

cve-icon Vulnrichment

Updated: 2026-08-25T17:19:29.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T16:16:42.930

Modified: 2026-08-28T18:56:34.447

Link: CVE-2021-47996

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-25T15:15:53Z

Links: CVE-2021-47996 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses