VDB
Sign up
LOW

GHSA-c2f4-jgmc-q2r5

REXML has DoS condition when parsing malformed XML file

Quick fix

GHSA-c2f4-jgmc-q2r5 — rexml: upgrade to the fixed version with the command below.

bundle update rexml

Details

### Impact

The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.

### Patches

REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.

### Workarounds

Don't parse untrusted XMLs.

### References

* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rexml
Introduced in: 3.3.3Fixed in: 3.4.2
Fixbundle update rexml

References