FixVibe

high

Nokogiri Affected by libxslt Use-After-Free Vulnerability (CVE-2019-18197)

Nokogiri before 1.10.5 can carry a libxslt use-after-free and uninitialized-data disclosure issue. FixVibe GitHub repo scans flag affected Nokogiri versions in Gemfile, Gemfile.lock, and gemspec files.

CVE-2019-18197GHSA-242x-7cm6-4w8jCWE-416CWE-908

Impact

Applications that depend on Nokogiri before 1.10.5 may include a libxslt release affected by CVE-2019-18197 / GHSA-242x-7cm6-4w8j [S2]. Treat this as dependency upgrade evidence, especially where Ruby code processes XML or XSLT from user-supplied, partner-controlled, or otherwise untrusted sources.

Root Cause

The issue is in libxslt, which Nokogiri can use for XSLT transformations [S1]. The public CVE record describes a pointer-management flaw in libxslt 1.1.33 that can lead to memory safety or uninitialized-data exposure conditions during XSLT processing [S1]. Nokogiri 1.10.5 updated its bundled libxslt dependency to the fixed release line referenced by the RubyGems advisory records [S2][S4].

Covered by FixVibe

FixVibe's GitHub repo scans flag Gemfile, Gemfile.lock, and .gemspec entries that resolve the nokogiri gem to a version before 1.10.5 [S2][S3][S4], with the file, version and fixed version.

Fix

Upgrade nokogiri to 1.10.5 or later [S2][S4]. Regenerate Gemfile.lock or gemspec constraints with the package manager that controls deployment, rebuild any Ruby app image, worker, CI cache, or host bundle that installs gems, and verify the deployed runtime resolves the fixed Nokogiri version. Review XML and XSLT processing paths so untrusted documents are rejected, sanitized, or restricted to trusted transforms.