<Vulnerability name="CVE-2025-71406">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-25T15:15:58</PublicDate>
    <Bugzilla id="2523577" url="https://bugzilla.redhat.com/show_bug.cgi?id=2523577" xml:lang="en:us">
nokogiri: libxslt: Nokogiri: Memory corruption via crafted XSLT
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-825</CWE>
    <Details xml:lang="en:us" source="Mitre">
Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking xpathCtxt-&gt;node) and CVE-2024-55549 (use-after-free related to excluded result prefixes/namespaces). Processing crafted XSLT can trigger memory corruption. Nokogiri 1.18.4 upgrades the bundled libxslt to 1.1.43 to resolve these issues.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Nokogiri, which bundles a vulnerable version of libxslt. This vulnerability involves a use-after-free condition that can be triggered by processing specially crafted Extensible Stylesheet Language Transformations (XSLT). A remote attacker could exploit this to cause memory corruption, potentially leading to a denial of service or other impacts.
    </Details>
    <Statement xml:lang="en:us">
This is an Important vulnerability. Red Hat products bundling Nokogiri versions prior to 1.18.4 are affected by use-after-free flaws in the integrated libxslt library. Processing specially crafted XSLT input could lead to memory corruption, potentially allowing for remote code execution or denial of service in applications that handle untrusted XSLT.
    </Statement>
    <Mitigation xml:lang="en:us">
To reduce the risk associated with this vulnerability, ensure that applications using Nokogiri do not process untrusted Extensible Stylesheet Language Transformations (XSLT) input. Implement strict input validation and only allow XSLT from trusted sources.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:red_hat_3scale_amp:2">
        <ProductName>Red Hat 3scale API Management Platform 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>3scale-amp2/backend-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_3scale_amp:2">
        <ProductName>Red Hat 3scale API Management Platform 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>3scale-amp2/system-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_3scale_amp:2">
        <ProductName>Red Hat 3scale API Management Platform 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>3scale-amp2/system-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_3scale_amp:2">
        <ProductName>Red Hat 3scale API Management Platform 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>3scale-amp2/toolbox-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_3scale_amp:2">
        <ProductName>Red Hat 3scale API Management Platform 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>3scale-amp2/zync-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:satellite:6">
        <ProductName>Red Hat Satellite 6</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rubygem-nokogiri</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:satellite:6">
        <ProductName>Red Hat Satellite 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>tfm-rubygem-amazing_print</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:satellite:6">
        <ProductName>Red Hat Satellite 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>tfm-rubygem-graphql</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2025-71406
https://nvd.nist.gov/vuln/detail/CVE-2025-71406
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-mrxw-mxhj-p664
https://www.vulncheck.com/advisories/nokogiri-before-use-after-free-via-libxslt
    </References>
</Vulnerability>