#nokogiri
Nokogiri, Loofah and Crass now compile to native code with Spinel, Matz's Ruby-to-C compiler. Same requires, same APIs, no Rails. An HTML sanitizer becomes a 2–3 MB binary that runs in 5–9 ms, byte-identical to the gems on their own test inputs.

intertwingly.net/blog/2026/09...
Nokogiri, Loofah and Crass, Compiled
intertwingly.net
September 29, 2026 at 11:38 PM
You were right, and it's 5 of 7 here. Campfire's TruffleRuby lane loads:

declared — puma, bcrypt, nio4r, json, openssl
not — sqlite3, nokogiri

sqlite3 is the hot one (a few hundred rows/request). --cexts-lock=false: 432 → 1,078 req/s at 5 threads
September 22, 2026 at 7:54 PM
Real talk tho, I still think my favorite episode was with the Nokogiri
September 19, 2026 at 12:16 AM
今年度から始まったサンキューちばフリーパスの英字版。

…養老渓谷と鋸山、どっちも複合名詞なのに、なんでYoro Valleyは分ち書きでNokogiriyamaは単一名詞として書かれてるんだろ。

Nokogiri Mountainじゃないかな、揃えるとしたら。
September 7, 2026 at 11:05 AM
On September 3, 1974, TV show 'Vicky the Viking' aired episode "Nokogiri ei no katakiuchi"
September 3, 2026 at 1:19 PM
日本やトルコ、イランなど一部の地域の鋸は引く方向に刃がついており、押し挽きが主流の中国とは対照的な構造をもつ。 Nihon ya Toruko, Iran nado ichibu no chiiki no nokogiri wa hiku hōkō ni ha ga tsuite ori, oshibiki ga shuryū no Chūgoku to wa taishōteki na kōzō o motsu.
September 2, 2026 at 1:42 PM
Forget the boring lists of school kanji because 鋸 (nokogiri), the saw, hides a bloodier secret.
September 2, 2026 at 1:42 PM
📌 CVE-2021-47996 - Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple v... https://www.cyberhub.blog/cves/CVE-2021-47996
CVE-2021-47996
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncod
www.cyberhub.blog
September 2, 2026 at 12:37 PM
📌 CVE-2023-54354 - Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer deref... https://www.cyberhub.blog/cves/CVE-2023-54354
CVE-2023-54354
Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/mal
www.cyberhub.blog
September 2, 2026 at 12:07 PM
📌 CVE-2022-50998 - Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption /... https://www.cyberhub.blog/cves/CVE-2022-50998
CVE-2022-50998
Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_
www.cyberhub.blog
September 2, 2026 at 11:37 AM
📌 CVE-2026-79770 - Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal an... https://www.cyberhub.blog/cves/CVE-2026-79770
CVE-2026-79770
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause expo
www.cyberhub.blog
September 2, 2026 at 11:07 AM
📌 CVE-2022-50999 - Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause... https://www.cyberhub.blog/cves/CVE-2022-50999
CVE-2022-50999
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information dis
www.cyberhub.blog
September 2, 2026 at 9:07 AM
📌 CVE-2022-51000 - Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVE... https://www.cyberhub.blog/cves/CVE-2022-51000
CVE-2022-51000
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-
www.cyberhub.blog
September 2, 2026 at 8:07 AM
CVE-2025-71407 - nokogiri
The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML definitions from untrusted…

Too many irrelevant or confusing CVEs? Use stackflag.com

#nokogiri #sparklemotion #CVE #infosec
CVE-2025-71407: Nokogiri can crash or be hijacked by crafted XML
The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML.
stackflag.com
August 25, 2026 at 11:00 PM
CVE-2024-58377 - nokogiri
Versions of the Nokogiri library earlier than 1.16.5 ship with an older copy of the libxml2 XML processor that contains a known weakness. The flaw is in a command‑line tool…

Too many irrelevant or confusing CVEs? Use stackflag.com

#nokogiri #sparklemotion #CVE #infosec
CVE-2024-58377: Nokogiri versions before 1.16.5 include vulnerable libxml2 component
Versions of the Nokogiri library earlier than 1.16.5 ship with an older copy of the libxml2 XML processor that contains a known weakness.
stackflag.com
August 25, 2026 at 11:00 PM
CVE-2024-58378 - nokogiri
Versions of Nokogiri before 1.15.6 and before 1.16.2 can crash when they read XML files that use DTD validation and XInclude features. The problem occurs only with the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#nokogiri #sparklemotion #CVE #infosec
CVE-2024-58378: Nokogiri XML Reader may crash on crafted XML files
Versions of Nokogiri before 1.15.6 and before 1.16.2 can crash when they read XML files that use DTD validation and XInclude features.
stackflag.com
August 25, 2026 at 10:30 PM
CVE-2022-51000 - nokogiri
If your Ruby application uses Nokogiri older than version 1.13.2, specially when it processes XML or XSL files from outside sources, an attacker could cause the program to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#nokogiri #sparklemotion #CVE #infosec
CVE-2022-51000: Nokogiri versions before 1.13.2 can be crashed by bad XML
If your Ruby application uses Nokogiri older than version 1.13.2, specially when it processes XML or XSL files from outside sources, an attacker could.
stackflag.com
August 25, 2026 at 10:30 PM
Nokogiri v1.13.4以前のバージョンに整数オーバーフロー脆弱性があります。攻撃者は巨大XMLファイルでメモリ書き込み異常を引き起こし、情報漏洩や改ざん、サービス不能状態を招く可能性があり…
CVE-2022-50999 CVSS 8.6 | HIGH
NVD - CVE-2022-50999
nvd.nist.gov
August 25, 2026 at 6:56 PM
Nokogiri 1.13.9より前のバージョンはlibxml2の脆弱性の影響を受ける。細工されたXML処理により、データ破損、サービス拒否、メモリ破損が引き起こされる可能性がある。
CVE-2022-50998 CVSS 7.5 | HIGH
NVD - CVE-2022-50998
nvd.nist.gov
August 25, 2026 at 6:54 PM
Nokogiri 1.11.4 未満(CRuby実装、バンドル版libxml2使用時)はlibxml2 2.9.10に脆弱性があり、XML処理でサービス拒否、情報漏洩、メモリ破損の可能性があります。
CVE-2021-47996 CVSS 7.5 | HIGH
NVD - CVE-2021-47996
nvd.nist.gov
August 25, 2026 at 6:52 PM
🚨 CVE-2025-71407 — CVSS 9.3 CRITICAL

Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validat...

🔎 https://stemshop.top/cve/CVE-2025-71407

#CVE #CyberSecurity #InfoSec
August 25, 2026 at 6:08 PM
🚨 CVE-2024-58378 — CVSS 9.3 CRITICAL

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a u...

🔎 https://stemshop.top/cve/CVE-2024-58378

#CVE #CyberSecurity #InfoSec
August 25, 2026 at 6:07 PM
🚨 CVE-2024-58377 — CVSS 9.3 CRITICAL

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xml...

🔎 https://stemshop.top/cve/CVE-2024-58377

#CVE #CyberSecurity #InfoSec
August 25, 2026 at 6:07 PM
🚨 CVE-2022-51000 — CVSS 9.3 CRITICAL

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1...

🔎 https://stemshop.top/cve/CVE-2022-51000

#CVE #CyberSecurity #InfoSec
August 25, 2026 at 6:07 PM
Next week to Fujiyoshida to walk up Fuji-san.
The third week to Hota to go up Mt Nokogiri and to swim in Tokyo Bay.
Otherwise staying in Tokyo. @missmerc.bsky.social is taking me to see the Yakult Swallows on Saturday.
Tomorrow I might catch the last hanabi matsuri.
August 10, 2026 at 12:07 PM