{"schema_version":"1.7.3","id":"GHSA-2rxp-v6pw-ch6m","published":"2024-10-28T14:10:18Z","modified":"2026-07-08T06:49:47.357118070Z","aliases":["CVE-2024-49761","CVE-2025-10990"],"related":["CGA-4fmh-g28c-xxpv"],"summary":"REXML ReDoS vulnerability","details":"### Impact\n\nThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between `&#` and `x...;` in a hex numeric character reference (`&#x...;`).\n\nThis does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.\n\n### Patches\n\nThe REXML gem 3.3.9 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nUse Ruby 3.2 or later instead of Ruby 3.1.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761/: An announce on www.ruby-lang.org","affected":[{"package":{"name":"rexml","ecosystem":"RubyGems","purl":"pkg:gem/rexml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.9"}]}],"versions":["3.1.7.3","3.1.8","3.1.9","3.1.9.1","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-2rxp-v6pw-ch6m/GHSA-2rxp-v6pw-ch6m.json"}}],"references":[{"type":"WEB","url":"https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49761"},{"type":"WEB","url":"https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f"},{"type":"PACKAGE","url":"https://github.com/ruby/rexml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-49761.yml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241227-0004"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761"}],"database_specific":{"cwe_ids":["CWE-1333"],"github_reviewed":true,"github_reviewed_at":"2024-10-28T14:10:18Z","nvd_published_at":"2024-10-28T15:15:05Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}]}