Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Nokogiri before 1.14.3 Null Pointer Dereference via libxml2 | nokogiri: libxml2: Nokogiri: Denial of Service via crafted XML schema |
| Metrics |
ssvc
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| References |
|
|
| Metrics |
cvssV4_0
|
Tue, 08 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resulting in a denial of service. Nokogiri 1.14.3 upgrades the packaged libxml2 to v2.10.4 to resolve these issues. | This CVE ID has been rejected as a duplicate. |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:* |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 25 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resulting in a denial of service. Nokogiri 1.14.3 upgrades the packaged libxml2 to v2.10.4 to resolve these issues. | |
| Title | Nokogiri before 1.14.3 Null Pointer Dereference via libxml2 | |
| First Time appeared |
Nokogiri
Nokogiri nokogiri |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokogiri
Nokogiri nokogiri |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T14:57:44.514Z
Reserved: 2026-01-10T01:51:52.987Z
Link: CVE-2023-54354
Updated:
Status : Rejected
Published: 2026-08-25T16:16:44.543
Modified: 2026-09-08T15:18:24.407
Link: CVE-2023-54354
OpenCVE Enrichment
Updated: 2026-08-25T17:15:05Z