Sploitus

CVE-2025-71346

No indexed exploits for CVE-2025-71346 yet

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity.

Affected products
Nokogiri, Libxml2
CVSS 4.0
8.7 HIGH
CVSS 3.1
2.9 LOW
EPSS
0.2% (8th percentile)
Weakness
CWE-125
NVD status
Awaiting Analysis
Published
2026-08-25
CVE-2025-71346 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-71346 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-71346 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.