{"id":"ROOT-OS-ALPINE-318-CVE-2024-41946","summary":"CVE-2024-41946 in ruby-rexml - Patched by Root","details":"Root has patched CVE-2024-41946 in the ruby-rexml package for Root:Alpine:3.18. Multiple fixed versions available.","modified":"2026-09-29T11:15:08.067421933Z","published":"2026-09-29T10:34:56Z","upstream":["CVE-2024-41946"],"database_specific":{"distro_version":"3.18","severity":"MEDIUM","source":"Root","distro":"alpine"},"affected":[{"package":{"name":"ruby-rexml","ecosystem":"Root:Alpine:3.18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.5-r30075"},{"fixed":"3.2.5-r30071"},{"fixed":"3.2.5-r30072"},{"fixed":"3.2.5-r30074"},{"fixed":"3.2.5-r30073"}]}],"database_specific":{"upstream_version":"3.2.5","all_fixed_versions":["3.2.5-r30075","3.2.5-r30071","3.2.5-r30072","3.2.5-r30074","3.2.5-r30073"],"root_patch_version":"r30075","root_patched":true,"total_fixed_versions":5,"source":"https://api.root.io/external/osv/ROOT-OS-ALPINE-318-CVE-2024-41946.json"}},{"package":{"name":"rootio-ruby-rexml","ecosystem":"Root:Alpine:3.18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.5-r30075"},{"fixed":"3.2.5-r30071"},{"fixed":"3.2.5-r30072"},{"fixed":"3.2.5-r30074"},{"fixed":"3.2.5-r30073"}]}],"database_specific":{"all_fixed_versions":["3.2.5-r30075","3.2.5-r30071","3.2.5-r30072","3.2.5-r30074","3.2.5-r30073"],"root_patch_version":"r30075","root_patched":true,"total_fixed_versions":5,"source":"https://api.root.io/external/osv/ROOT-OS-ALPINE-318-CVE-2024-41946.json","upstream_version":"3.2.5"}}],"schema_version":"1.9.0"}