{"schema_version":"1.7.3","id":"GHSA-c2f4-jgmc-q2r5","published":"2025-09-17T18:26:48Z","modified":"2026-02-04T02:40:25.476238Z","aliases":["CVE-2025-58767"],"related":["CGA-q7qx-ch7j-v954"],"summary":"REXML has DoS condition when parsing malformed XML file","details":"### Impact\n\nThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nREXML gems 3.4.2 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org","affected":[{"package":{"name":"rexml","ecosystem":"RubyGems","purl":"pkg:gem/rexml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.3"},{"fixed":"3.4.2"}]}],"versions":["3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9","3.4.0","3.4.1"],"database_specific":{"last_known_affected_version_range":"<= 3.4.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-c2f4-jgmc-q2r5/GHSA-c2f4-jgmc-q2r5.json"}}],"references":[{"type":"WEB","url":"https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58767"},{"type":"WEB","url":"https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23"},{"type":"PACKAGE","url":"https://github.com/ruby/rexml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2025-58767.yml"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767"}],"database_specific":{"cwe_ids":["CWE-400","CWE-776"],"github_reviewed":true,"github_reviewed_at":"2025-09-17T18:26:48Z","nvd_published_at":"2025-09-17T18:15:52Z","severity":"LOW"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}