Unchecked Return Value in Nokogiri's Canonicalize Method Exposes Vulnerability
CVE-2026-79772
6.9MEDIUM
What is CVE-2026-79772?
Nokogiri versions prior to 1.19.1 contain a flaw in the canonicalize method, where the library fails to properly handle the return value from xmlC14NExecute. Instead of raising an exception on failure, it returns an empty string. This oversight allows malicious actors to exploit the vulnerability by crafting invalid canonicalized XML inputs that could be wrongly accepted as valid. Such a flaw presents a significant risk as it undermines the integrity of signature validation processes in downstream SAML libraries.
Affected Version(s)
nokogiri 1.5.1 < 1.19.1
nokogiri 1.19.1
