CVE Feed

    Dashboard / CVE / CVE-2025-58767

    CVE-2025-58767

    REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.

    Published:Sep 17, 2025
    Last Modified:Sep 30, 2025
    EPS:Sep 17, 2025
    EPSS Score:0.00041
    CVSS Score:5.3

    Affected Products

    Vendor
    Ruby
    Product
    Rexml
    Vendor
    Ruby-lang
    Product
    Rexml

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High