← Vulnerability feed

Vulnerability record · CVE-2021-41098 · published 27 September 2021

CVE-2021-41098: Nokogiri xml external entity (xxe) vulnerability

Nokogiri · Nokogiri

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who parse untrusted documents using any of these classes are affected: Nokogiri::XML::SAX::Parse, Nokogiri::HTML4::SAX::Parser or its alias Nokogiri::HTML::SAX::Parser, Nokogiri::XML::SAX::PushParser, and Nokogiri::HTML4::SAX::PushParser or its alias Nokogiri::HTML::SAX::PushParser. JRuby users should upgrade to Nokogiri v1.12.5 or later to receive a patch for this issue. There are no workarounds available for v1.12.4 or earlier. CRuby users are not affected.

7.5 CVSS 3.1 High EPSS 1.4% · top 27.7% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who parse untrusted documents using any of these classes are affected: Nokogiri::XML::SAX::Parse, Nokogiri::HTML4::SAX::Parser or its alias Nokogiri::HTML::SAX::Parser, Nokogiri::XML::SAX::PushParser, and Nokogiri::HTML4::SAX::PushParser or its alias Nokogiri::HTML::SAX::PushParser. JRuby users should upgrade to Nokogiri v1.12.5 or later to receive a patch for this issue. There are no workarounds available for v1.12.4 or earlier. CRuby users are not affected.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41098 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5477Nokogiri os command injection vulnerabilityA command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Pro…EPSS 5.9%8.7CVE-2026-79770Nokogiri inefficient regular expression (redos) vulnerabilityNokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal a…EPSS 0.49%8.2CVE-2022-29181Nokogiri type confusion vulnerabilityNokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX …EPSS 3.2%7.5CVE-2022-23476Nokogiri unchecked return value vulnerabilityNokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from…EPSS 1.8%7.5CVE-2022-24836Nokogiri uncontrolled resource consumption vulnerabilityNokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to exce…EPSS 3.5%7.5CVE-2018-25032zlib deflate out-of-bounds write on distant matcheszlib before 1.2.12 allows memory corruption when deflating (compressing) input that contains many distant matches, an out-of-bounds write (CWE-787). …EPSS 52%analysed7.5CVE-2012-6685Nokogiri vulnerabilityNokogiri before 1.5.4 is vulnerable to XXE attacksEPSS 2.2%6.9CVE-2026-79771Nokogiri memory leak vulnerabilityNokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Att…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2021-41098), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.