
🚨Critical - Nokogiri libxml2 DTD/XSD Validation Memory Corruption (CVE-2025-71407) In Nokogiri’s bundled libxml2, DTD validation error reporting overflows a stack buffer on long QName prefixes, and XML Schema validation can hit a use-after-free when parsing untrusted XSD. Remote attackers can feed malicious DTD/XSD via XML parsing/validation to crash the process or potentially achieve RCE. Non-validating XML parsing is not impacted. 👉Affected: nokogiri < 1.18.3 | Upgrade to 1.18.3
Post summary
The post announces a critical memory corruption vulnerability (CVE‑2025‑71407) in Nokogiri’s libxml2, detailing stack overflow and use‑after‑free conditions, and advises users to upgrade to version 1.18.3.

