{"id":"CVE-2024-41123","aliases":["GHSA-r55c-59qm-vjw6"],"url":"https://o3.security/vulnerability/CVE-2024-41123","summary":"REXML DoS vulnerability","details":"### Impact\n\nThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`.\n\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh : This is a similar vulnerability\n* https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 : This is a similar vulnerability\n* https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123/: An announce on www.ruby-lang.org","published":"2024-08-01T14:18:43.611Z","modified":"2026-08-12T03:51:18.066003139Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"rexml","fixedVersion":"3.3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41123.json"},{"type":"ADVISORY","url":"https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8"},{"type":"ADVISORY","url":"https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6"},{"type":"ADVISORY","url":"https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41123"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241227-0005/"},{"type":"PACKAGE","url":"https://github.com/ruby/rexml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-41123.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241227-0005"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.066003139Z"}}