REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4018-1 | ruby2.7 security update |
EUVD |
EUVD-2024-2501 | REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability. |
Github GHSA |
GHSA-5866-49gr-22v4 | REXML DoS vulnerability |
Ubuntu USN |
USN-7091-1 | Ruby vulnerabilities |
Ubuntu USN |
USN-7091-2 | Ruby vulnerabilities |
Ubuntu USN |
USN-7840-1 | Ruby vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 17 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Sep 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 |
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_e4s:8.6::highavailability cpe:/a:redhat:rhel_eus:8.8::highavailability cpe:/a:redhat:rhel_tus:8.6::highavailability |
|
| Vendors & Products |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
Mon, 16 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8::highavailability | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T20:38:34.071Z
Reserved: 2024-07-24T16:51:40.948Z
Link: CVE-2024-41946
Updated: 2025-11-03T20:38:34.071Z
Status : Modified
Published: 2024-08-01T15:15:14.100
Modified: 2025-11-03T21:16:17.533
Link: CVE-2024-41946
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN