Unchecked Return Value in Nokogiri's Canonicalize Method Exposes Vulnerability
CVE-2026-79772

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79772?

Nokogiri versions prior to 1.19.1 contain a flaw in the canonicalize method, where the library fails to properly handle the return value from xmlC14NExecute. Instead of raising an exception on failure, it returns an empty string. This oversight allows malicious actors to exploit the vulnerability by crafting invalid canonicalized XML inputs that could be wrongly accepted as valid. Such a flaw presents a significant risk as it undermines the integrity of signature validation processes in downstream SAML libraries.

Affected Version(s)

nokogiri 1.5.1 < 1.19.1

nokogiri 1.19.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.