mediumVulnerability

GHSA-5prr-v3j2-97mh

### Summary `Nokogiri::XML::NodeSet#[]` (and its alias `#slice`) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby it is not memory-unsafe but returns an incorrect node. Nokogiri 1.19.4 performs the bounds check against the full-width index. ### Severity The Nokogiri maintainers have evaluated this as medium severity. Exploitation requires an application to pass an attacker-controlled integer to `NodeSet#[]`. The primary impact is a controlled crash (denial of service), with potential for memory disclosure on CRuby. On JRuby, Nokogiri is not affected by this vulnerability. ### Mitigation Upgrade to Nokogiri 1.19.4 or later. As a workaround, applications that index a `NodeSet` with externally-supplied integers can validate the index against `node_set.length` before use, or avoid passing untrusted values as an index. ### Credit This issue was responsibly reported by Zheng Yu from depthfirst.com.

Properties

ghsa_id
GHSA-5prr-v3j2-97mh
severity
medium
summary
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
cve_id
GHSA-5prr-v3j2-97mh
is_ghsa_only
true
ghsa_published
2026-06-19T16:36:42Z
source_url
https://github.com/advisories/GHSA-5prr-v3j2-97mh
ghsa_updated
2026-06-19T16:36:42Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]rubygems/nokogiri

AFFECTS (1)

[Software]rubygems/nokogiri

HAS_WEAKNESS (2)

[Weakness]Integer Overflow or Wraparound
[Weakness]Out-of-bounds Read

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5prr-v3j2-97mh — Ninja Signal Threat Intelligence | Ninja Signal