CVE-2025-58767 - CVE House
Back to Database
Status published Low CVE-2025-58767

REXML has a DoS condition when parsing malformed XML file

Vulnerability Description

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58767

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rexml
Vulnerable Versions:
>= 3.3.3, < 3.4.2

Timeline

Official Publish: September 17th, 2025
Last Modified: September 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)