SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2024-58378

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

Nokogiri versions prior to 1.15.6 and 1.16.x before 1.16.2 are vulnerable to a critical use-after-free vulnerability in the xmlTextReader module of the packaged libxml2, which can be exploited when processing specially crafted XML documents with DTD validation and XInclude expansion enabled. This vulnerability can lead to potential application crashes or arbitrary code execution, posing significant risks to applications relying on these versions. Developers and organizations using affected Nokogiri versions should prioritize upgrading to the patched releases to mitigate these risks.

CVE
CVE-2024-58378
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected as a duplicate.