CVE-2024-41123

MEDIUM

REXML < 3.2.7 and 3.3.0-3.3.2 - Denial of Service via Malformed XML Parsing

Title source: llm
STIX 2.1

Description

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
ruby-lang/rexml < 3.2.7
rubygems/rexml 0 - 3.3.3RubyGems
Published Aug 01, 2024
Tracked Since Feb 18, 2026