Skip to main content

Vendor/product archive

ruby-lang / rexml CVEs

Beta · best-effort

8 CVEs tagged to ruby-lang / rexml0 Critical, 1 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2025-58767

Published Sep 17, 2025

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-41946

Published Aug 1, 2024

REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41123

Published Aug 1, 2024

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35176

Published May 16, 2024

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1