Description
REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5
Patch x_refsource_misc
https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23
Scores
CVSS v3
5.3
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (2)
ruby-lang/rexml
3.3.3 - 3.4.2
rubygems/rexml
3.3.3 - 3.4.2RubyGems
Published
Sep 17, 2025
Tracked Since
Feb 18, 2026