CVE-2024-58377
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not provide or expose the xmllint tool where the issue occurs.
- CVSS 4.0
- 6.8 MEDIUM
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.2% (9th percentile)
- Weakness
- CWE-125
- NVD status
- Awaiting Analysis
- Published
- 2026-08-25
CVE-2024-58377 at NVD
No indexed exploits for CVE-2024-58377 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-58377 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.