SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-71406

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

Nokogiri versions prior to 1.18.4 are vulnerable due to bundling an outdated version of libxslt, which contains critical use-after-free vulnerabilities that can lead to memory corruption when processing malicious XSLT. This high-severity flaw poses significant risks for applications relying on Nokogiri for XML processing, particularly those exposed to untrusted input. Developers and organizations using affected versions should prioritize upgrading to Nokogiri 1.18.4 or later to mitigate potential exploitation.

CVE
CVE-2025-71406
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected as a duplicate.