CVE-2025-58767
ADVISORY - githubSummary
Impact
The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.
Patches
REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.
Workarounds
Don't parse untrusted XMLs.
References
- https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org
Common Weakness Enumeration (CWE)
Uncontrolled Resource Consumption
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
NIST
3.9
CVSS SCORE
1.2lowGitHub
CVSS SCORE
1.2lowAlpine
-
Debian
-
CVSS SCORE
N/AlowUbuntu
3.9
CVSS SCORE
5.3lowAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AlowRed Hat
3.9
CVSS SCORE
5.3mediumRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumChainguard
CGA-2765-8r55-8wj7
-
Chainguard
CGA-2p3g-89rc-jcvh
-
Chainguard
CGA-3qc9-9hj9-ch8r
-
Chainguard
CGA-74qh-p38g-mc54
-
Chainguard
CGA-8vv6-82pf-cf55
-
Chainguard
CGA-9mjq-x3cw-wpq8
-
Chainguard
CGA-cq62-jf4j-5cx2
-
Chainguard
CGA-hjr9-533q-3hqp
-
Chainguard
CGA-hm38-w55m-ch3j
-
Chainguard
CGA-mhjj-458w-v476
-
Chainguard
CGA-mjjp-mpvp-wv53
-
Chainguard
CGA-p4qj-qxwh-56jg
-
Chainguard
CGA-q7qx-ch7j-v954
-
Chainguard
CGA-rc5j-r65f-rc4v
-
Chainguard
CGA-x388-957j-vf83
-
Chainguard
CGA-xjr6-mqp3-qgp3
-
Photon
CVE-2025-58767
-
CVSS SCORE
5.3mediumminimos
MINI-32f4-q38f-265p
-
minimos
MINI-5f99-r283-2wqp
-
minimos
MINI-5h4w-q34g-h7xr
-
minimos
MINI-6g55-h792-9q8v
-
minimos
MINI-6j48-8p6h-vrc3
-
minimos
MINI-899g-gjvg-6v3r
-
minimos
MINI-8m63-q8qf-32m8
-
minimos
MINI-9m43-p63c-cq92
-
minimos
MINI-c45x-3vgw-5c9v
-
minimos
MINI-f4qj-5987-x4x3
-
minimos
MINI-h2xp-95vc-wm58
-
minimos
MINI-j2vw-xgpx-r8c7
-
minimos
MINI-m86r-qphm-hjq2
-
minimos
MINI-mcmw-6hhq-fqj2
-
minimos
MINI-mcq5-4qg9-w4cg
-
minimos
MINI-qhrq-67q2-75xg
-
minimos
MINI-qrgc-hv33-22vq
-
minimos
MINI-rc45-4v34-5mgr
-
minimos
MINI-w4c2-mq72-v5cx
-