{"id":"AZL-42052","summary":"CVE-2024-35176 affecting package ruby for versions less than 3.3.3-1","details":" REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `\u003c`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.","modified":"2026-04-01T05:14:27.427124Z","published":"2024-05-16T16:15:09Z","upstream":["CVE-2024-35176"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35176"}],"affected":[{"package":{"name":"ruby","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/ruby"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42052.json"}}],"schema_version":"1.7.5"}