Loading HuntDB...

GHSA-c2f4-jgmc-q2r5

GitHub Security Advisory

REXML has DoS condition when parsing malformed XML file

✓ GitHub Reviewed LOW Has CVE

Advisory Details

### Impact

The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.
If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.

### Patches

REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.

### Workarounds

Don't parse untrusted XMLs.

### References

* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org

Affected Packages

RubyGems rexml
Affected versions: 3.3.3 (fixed in 3.4.2)

Related CVEs

Key Information

GHSA ID
GHSA-c2f4-jgmc-q2r5
Published
September 17, 2025 6:26 PM
Last Modified
September 17, 2025 8:00 PM
CVSS Score
2.5 /10
Primary Ecosystem
RubyGems
Primary Package
rexml
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.