Impact
Applications that depend on Nokogiri before 1.10.5 may include a libxslt release affected by CVE-2019-18197 / GHSA-242x-7cm6-4w8j [S2]. Treat this as dependency upgrade evidence, especially where Ruby code processes XML or XSLT from user-supplied, partner-controlled, or otherwise untrusted sources.
Root Cause
The issue is in libxslt, which Nokogiri can use for XSLT transformations [S1]. The public CVE record describes a pointer-management flaw in libxslt 1.1.33 that can lead to memory safety or uninitialized-data exposure conditions during XSLT processing [S1]. Nokogiri 1.10.5 updated its bundled libxslt dependency to the fixed release line referenced by the RubyGems advisory records [S2][S4].
Covered by FixVibe
FixVibe's GitHub repo scans flag Gemfile, Gemfile.lock, and .gemspec entries that resolve the nokogiri gem to a version before 1.10.5 [S2][S3][S4], with the file, version and fixed version.
Fix
Upgrade nokogiri to 1.10.5 or later [S2][S4]. Regenerate Gemfile.lock or gemspec constraints with the package manager that controls deployment, rebuild any Ruby app image, worker, CI cache, or host bundle that installs gems, and verify the deployed runtime resolves the fixed Nokogiri version. Review XML and XSLT processing paths so untrusted documents are rejected, sanitized, or restricted to trusted transforms.
