Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resulting in a denial of service. Nokogiri 1.14.3 upgrades the packaged libxml2 to v2.10.4 to resolve these issues.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54354.json",
"cwe_ids": [
"CWE-476"
],
"cna_assigner": "VulnCheck"
}[
{
"id": "CVE-2023-54354-49d37df2",
"target": {
"function": "xmlSchemaResolveElementReferences",
"file": "xmlschemas.c"
},
"deprecated": false,
"digest": {
"function_hash": "161823131667449630370724922190556095829",
"length": 1316.0
},
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/4c6922f763ad958c48ff66f82823ae21f2e92ee6",
"signature_type": "Function"
},
{
"id": "CVE-2023-54354-93aea704",
"target": {
"function": "xmlDictComputeFastKey",
"file": "dict.c"
},
"deprecated": false,
"digest": {
"function_hash": "267970420252725130199376407402483825008",
"length": 571.0
},
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/09a2dd453007f9c7205274623acdd73747c22d64",
"signature_type": "Function"
},
{
"id": "CVE-2023-54354-c5752451",
"target": {
"file": "xmlschemas.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"308981022804931015236413879421957310638",
"282178084622988746890881910680625520695",
"50271736739838765844818037174763357243",
"198715064733683011505754465168917481346",
"69219023379864035696646291254384072462"
]
},
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/4c6922f763ad958c48ff66f82823ae21f2e92ee6",
"signature_type": "Line"
},
{
"id": "CVE-2023-54354-ef21c1eb",
"target": {
"file": "dict.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"19185847648471670323475216725842154505",
"273593918359875311050534871051271330899",
"160297338630813304163117051522217321186",
"116158295440288060980015079180399826565"
]
},
"signature_version": "v1",
"source": "https://github.com/gnome/libxml2/commit/09a2dd453007f9c7205274623acdd73747c22d64",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54354.json"
"2026-08-30T08:13:43Z"