Vulnerability Description
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokogiri | Nokogiri | >= 1.5.1, < 1.19.1 |
Related Weaknesses (CWE)
References
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-853Vendor Advisory
- https://www.vulncheck.com/advisories/nokogiri-before-unchecked-return-value-canoThird Party Advisory
FAQ
What is CVE-2026-79772?
CVE-2026-79772 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can explo...
How severe is CVE-2026-79772?
CVE-2026-79772 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79772?
Check the references section above for vendor advisories and patch information. Affected products include: Nokogiri Nokogiri.