VendorsRuby-langrexmlany version
Vulnerabilities

Ruby-lang Rexml any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-28965
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Published 2021-04-21 · Modified
7.5EPSS 0.051
CVE-2024-49761
REXML ReDoS vulnerability
Published 2024-10-28 · Modified
7.5EPSS 0.014
CVE-2024-41123
REXML DoS vulnerability
Published 2024-08-01 · Modified
7.5EPSS 0.013
CVE-2024-41946
REXML DoS vulnerability
Published 2024-08-01 · Modified
7.5EPSS 0.012
CVE-2024-43398
REXML denial of service vulnerability
Published 2024-08-22 · Modified
5.9EPSS 0.012
CVE-2024-35176
REXML contains a denial of service vulnerability
Published 2024-05-16 · Modified
5.3EPSS 0.021
CVE-2025-58767
REXML has a DoS condition when parsing malformed XML file
Published 2025-09-17 · Analyzed
5.3EPSS 0.002
CVE-2024-39908
Denial of service in REXML
Published 2024-07-16 · Modified
4.3EPSS 0.015