lowVulnerability

GHSA-wjv4-x9w8-wm3h

### Summary `Nokogiri::XML::Document#root=` validated only that the new root was a `Nokogiri::XML::Node`, allowing a DTD node to be set as the document root. The result is a heap use-after-free during garbage collection or finalization, leading to an invalid memory read or potentially a segfault. Nokogiri 1.19.4 restricts `Document#root=` to element nodes, raising `TypeError` for any other node type. This memory-safety issue affects only the CRuby implementation (libxml2). The JRuby implementation was not affected; the same input validation was added there for behavioral parity. ### Severity The Nokogiri maintainers have evaluated this as low severity. This is only triggered by a programming error. It requires application code to assign a non-element node such as a DTD as the document root via `Document#root=`. Nokogiri 1.19.4 now raises `TypeError` instead of allowing a use-after-free. It cannot be triggered by untrusted input or through normal use of the public API. ### Mitigation Upgrade to Nokogiri 1.19.4 or later. As a workaround, applications that cannot upgrade should avoid assigning a DTD (or any non-element node) via `Document#root=`. ### Credit This issue was responsibly reported by Zheng Yu from depthfirst.com.

Properties

ghsa_id
GHSA-wjv4-x9w8-wm3h
severity
low
summary
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
cve_id
GHSA-wjv4-x9w8-wm3h
is_ghsa_only
true
ghsa_published
2026-06-19T16:36:59Z
source_url
https://github.com/advisories/GHSA-wjv4-x9w8-wm3h
ghsa_updated
2026-06-19T16:37:01Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rubygems/nokogiri

AFFECTS (1)

[Software]rubygems/nokogiri

HAS_WEAKNESS (1)

[Weakness]Use After Free

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph