CVE-2025-71407: Nokogiri Bundled Vulnerable Libxml2

Bundled libxml2 version prior to 2.13.6 is vulnerable to DTD stack buffer overflow and XML Schema use-after-free.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0YAML
greprules fetch cve-2025-71407-nokogiri-bundled-vulnerable-libxml2 --engine opengrep

Description

Bundled libxml2 version prior to 2.13.6 is vulnerable to DTD stack buffer overflow and XML Schema use-after-free.