{"id":"CVE-2025-58767","aliases":["GHSA-c2f4-jgmc-q2r5"],"url":"https://o3.security/vulnerability/CVE-2025-58767","summary":"REXML has a DoS condition when parsing malformed XML file","details":"### Impact\n\nThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.\nIf you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.\n\n### Patches\n\nREXML gems 3.4.2 or later include the patches to fix these vulnerabilities.\n\n### Workarounds\n\nDon't parse untrusted XMLs.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org","published":"2025-09-17T17:45:58.118Z","modified":"2026-08-12T03:51:18.938211178Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"rexml","fixedVersion":"3.4.2"}],"fix":{"url":"https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23","label":"ruby/rexml@5859bde"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58767.json"},{"type":"ADVISORY","url":"https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58767"},{"type":"FIX","url":"https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23"},{"type":"PACKAGE","url":"https://github.com/ruby/rexml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2025-58767.yml"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.938211178Z"}}