PT-2025-38243 · Rexml+6 · Rexml+6
Sofiaaberegg
·
Publicado
2025-09-17
·
Atualizado
2026-06-08
·
CVE-2025-58767
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
REXML versions 3.3.3 through 3.4.1
Description
REXML, an XML toolkit for Ruby, is susceptible to a denial-of-service issue when processing XML data containing multiple XML declarations. Parsing untrusted XMLs may lead to this issue.
Recommendations
Update to REXML version 3.4.2 or later.
Avoid parsing untrusted XMLs.
Exploit
Correção
DoS
Resource Exhaustion
XML Entity Expansion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Almalinux
Centos
Debian
Rexml
Red Hat
Red Os
Rocky Linux