Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-bounds read (CVE-2021-3518). Processing crafted XML documents may lead to denial of service, information disclosure, or memory corruption.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47996.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"125923364555687102912767750593616075062",
"164402031157988608807981467698484062586",
"187480151731575691958788539215601771876",
"198926099027557728522349673134118447470"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-0cb4c5da",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/1358d157d0bd83be1dfe356a69213df9fac0b539",
"target": {
"file": "xmllint.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"247568056470202954226467748573418683172",
"94265484478106808140284082942404196729",
"54827508396231888230909548411994015125",
"279820038266218910920837730438313773675"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-2681a3f2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5",
"target": {
"file": "parser.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "133584636054340721205278925695833658201",
"length": 3540
},
"id": "CVE-2021-47996-3d708e2c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2",
"target": {
"file": "entities.c",
"function": "xmlEncodeEntitiesInternal"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "129795723050783868420429153906754155297",
"length": 1498
},
"id": "CVE-2021-47996-4e1d4e57",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/1098c30a040e72a4654968547f415be4e4c40fe7",
"target": {
"file": "xinclude.c",
"function": "xmlXIncludeDoProcess"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"238830279518026173601265985036679831221",
"6818339520559522538802628149446565204",
"21168215039705633172313227177812164754",
"44368582528979308298264734089416623463"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-6c0b3bb4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a",
"target": {
"file": "xmlschemas.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "72281996671305061154380570581536082488",
"length": 878
},
"id": "CVE-2021-47996-70f543c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a",
"target": {
"file": "xmlschemas.c",
"function": "xmlSchemaPreRun"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "318309956330829112293536792403977466123",
"length": 4010
},
"id": "CVE-2021-47996-8b9baf91",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5",
"target": {
"file": "parser.c",
"function": "xmlStringLenDecodeEntities"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"139217053892453545114406503002699038551",
"74174908839482910117114283962298867577",
"12712912407859303312203914586923544226",
"177575747721188392079589196392735439354",
"221866373724369158298727459108826691197",
"154882006815943080874703791132029998543"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-a0bae2e0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2",
"target": {
"file": "entities.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"168672058864961257859405146754354472187",
"64644107898846976266284128143066975089",
"182440086416972751708829220127142151095"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-abd1bcbd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2",
"target": {
"file": "xmllint.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"251243055166309716996962376314600332998",
"247021566701966566980313579297150334381",
"226559000756074575733463851249290972653",
"147375703684160506692803477328459167434",
"235123860312544971819592858258290679121",
"292652530897578466916550773007602664398"
],
"threshold": 0.9
},
"id": "CVE-2021-47996-c8855bc2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/1098c30a040e72a4654968547f415be4e4c40fe7",
"target": {
"file": "xinclude.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "333089290179452094192545213626485405871",
"length": 227
},
"id": "CVE-2021-47996-d5396ad3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2",
"target": {
"file": "xmllint.c",
"function": "xmlHTMLEncodeSend"
}
}
]
"2026-09-03T08:11:20Z"
{
"cpe": "cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.11.4"
}
],
"source": "CPE_RANGE"
}