#VU115794 Resource exhaustion in REXML - CVE-2025-58767
Published: September 18, 2025
REXML
rubygems.org
Description
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing invalid XML containing multiple XML declarations. A local attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.