{"id":"GHSA-c2f4-jgmc-q2r5","summary":"REXML has DoS condition when parsing malformed XML file","details":"### Impact\n\nThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nREXML gems 3.4.2 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org","aliases":["CVE-2025-58767"],"modified":"2026-07-17T21:16:46.534545937Z","published":"2025-09-17T18:26:48Z","database_specific":{"github_reviewed_at":"2025-09-17T18:26:48Z","nvd_published_at":"2025-09-17T18:15:52Z","cwe_ids":["CWE-400","CWE-776"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58767"},{"type":"WEB","url":"https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23"},{"type":"PACKAGE","url":"https://github.com/ruby/rexml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2025-58767.yml"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767"}],"affected":[{"package":{"name":"rexml","ecosystem":"RubyGems","purl":"pkg:gem/rexml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.3"},{"fixed":"3.4.2"}]}],"versions":["3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9","3.4.0","3.4.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.4.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-c2f4-jgmc-q2r5/GHSA-c2f4-jgmc-q2r5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}