{"id":"AZL-42076","summary":"CVE-2024-35176 affecting package rubygem-rexml for versions less than 3.2.7-1","details":" REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `\u003c`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.","modified":"2026-04-01T05:14:43.172378Z","published":"2024-05-16T16:15:09Z","upstream":["CVE-2024-35176"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35176"}],"affected":[{"package":{"name":"rubygem-rexml","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/rubygem-rexml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.7-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42076.json"}}],"schema_version":"1.7.5"}