PT-2025-38243 · Rexml+6 · Rexml+6
Sofiaaberegg
·
Published
2025-09-17
·
Updated
2026-03-26
·
CVE-2025-58767
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
REXML versions 3.3.3 through 3.4.1
Description
REXML, an XML toolkit for Ruby, is susceptible to a denial-of-service issue when processing XML data containing multiple XML declarations. Parsing untrusted XMLs may lead to this issue.
Recommendations
Update to REXML version 3.4.2 or later.
Avoid parsing untrusted XMLs.
Exploit
Fix
DoS
XML Entity Expansion
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Rexml
Red Hat
Red Os
Rocky Linux