<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:23:09.859955+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:23062</id>
    <title>ALSA-2025:23062 — Moderate: ruby:3.3 security update</title>
    <updated>2026-10-04T09:23:10.095338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* resolv: Denial of Service in resolv gem (CVE-2025-24294)
  * rexml: REXML denial of service (CVE-2025-58767)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:23062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-58767</id>
    <title>BELL-CVE-2025-58767</title>
    <updated>2026-10-04T09:23:10.095549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: ruby-rexml, Alpaquita:stream: ruby-rexml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-58767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</id>
    <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T09:23:10.095590+00:00</updated>
    <content>certfr-2025-avi-0967</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-sz82695</id>
    <title>CLEANSTART-2026-SZ82695 — Security fix for CVE-2025-58767 applied in: ruby 3.2.10-r0</title>
    <updated>2026-10-04T09:23:10.095621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby</p>
<p>Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-sz82695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252909</id>
    <title>EUVD-2026-252909</title>
    <updated>2026-10-04T09:23:10.095657+00:00</updated>
    <content>EUVD-2026-252909</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58767</id>
    <title>fkie_cve-2025-58767</title>
    <updated>2026-10-04T09:23:10.095678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c2f4-jgmc-q2r5</id>
    <title>GHSA-c2f4-jgmc-q2r5 — REXML has DoS condition when parsing malformed XML file</title>
    <updated>2026-10-04T09:23:10.095720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rexml</p>
<p>### Impact</p>
<p>The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.
If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.</p>
<p>### Patches</p>
<p>REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.</p>
<p>### Workarounds</p>
<p>Don't parse untrusted XMLs.</p>
<p>### References</p>
<p>* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c2f4-jgmc-q2r5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-58767</id>
    <title>msrc_CVE-2025-58767 — REXML has a DoS condition when parsing malformed XML file</title>
    <updated>2026-10-04T09:23:10.095749+00:00</updated>
    <content>msrc_CVE-2025-58767</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-58767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2655</id>
    <title>OESA-2025-2655 — ruby security update</title>
    <updated>2026-10-04T09:23:10.095767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP2: ruby, openEuler:20.03-LTS-SP4: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).

Security Fix(es):</p>
<p>REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.(CVE-2025-58767)</p>
<p>Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer via the use of the `+` operator when combining URIs. An attacker can obtain sensitive user credentials by crafting a URI that, when merged with another, results in the unintended exposure of authentication information.</p>
<p>**Note:** This vulnerability is a bypass of the fix to CVE-2025-27221.(CVE-2025-61594)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15828-1</id>
    <title>openSUSE-SU-2025:15828-1 — libruby3_4-3_4-3.4.8-1.1 on GA media</title>
    <updated>2026-10-04T09:23:10.095801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libruby3_4-3_4-3.4.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15828-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:23140</id>
    <title>RHSA-2025:23140 — Red Hat Security Advisory: ruby:3.3 security update</title>
    <updated>2026-10-04T09:23:10.095817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rexml: REXML denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:23140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58767</id>
    <title>UBUNTU-CVE-2025-58767</title>
    <updated>2026-10-04T09:23:10.095832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: ruby3.2, Ubuntu:25.10: ruby3.3, Ubuntu:26.04:LTS: ruby3.3</p>
<p>REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2083</id>
    <title>WID-SEC-W-2025-2083 — Ruby: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T09:23:10.095858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2083"/>
  </entry>
</feed>
