CVE-2024-35176

MEDIUM5.3EPSS 8.4%

ruby2.7 - security update

Published: 5/16/2024Modified: 3/9/2026
Also known as:GHSA-vg3r-rm7w-2xghCGA-94h4-f4cw-hpp4DEBIAN-CVE-2024-35176DEBIAN-CVE-2024-39908DEBIAN-CVE-2024-41123DEBIAN-CVE-2024-41946DEBIAN-CVE-2024-43398DEBIAN-CVE-2024-49761DLA-4018-1

Description

### Impact The REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many `>`s in an attribute value. If you need to parse untrusted XMLs, you may be impacted to this vulnerability. ### Patches The REXML gem 3.2.7 or later include the patch to fix this vulnerability. ### Workarounds Don't parse untrusted XMLs. ### References * https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176/

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (8)