
Nokogiri (Ruby's XML/HTML parser) just patched CVE-2026-57235: integer truncation in NodeSet indexing. If you're running Rails or any Ruby app that parses XML, here's what to check Saturday.
Post summary
The tweet announces that Nokogiri has patched CVE‑2026‑57235, an integer truncation flaw in NodeSet indexing, for Ruby applications parsing XML.
