<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:16:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:23062 — Moderate: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:23062</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: Denial of Service in resolv gem (CVE-2025-24294)
  * rexml: REXML denial of service (CVE-2025-58767)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: Denial of Service in resolv gem (CVE-2025-24294)
  * rexml: REXML denial of service (CVE-2025-58767)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:23062</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-58767</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-58767</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-rexml, Alpaquita:stream: ruby-rexml&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-rexml, Alpaquita:stream: ruby-rexml&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-58767</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</link>
      <description>certfr-2025-avi-0967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-SZ82695 — Security fix for CVE-2025-58767 applied in: ruby 3.2.10-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-sz82695</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-sz82695</guid>
    </item>
    <item>
      <title>EUVD-2026-252909</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252909</link>
      <description>EUVD-2026-252909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252909</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58767</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58767</link>
      <description>&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58767</guid>
    </item>
    <item>
      <title>GHSA-c2f4-jgmc-q2r5 — REXML has DoS condition when parsing malformed XML file</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c2f4-jgmc-q2r5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rexml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.
If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Don&amp;#39;t parse untrusted XMLs.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rexml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations.
If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;REXML gems 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Don&amp;#39;t parse untrusted XMLs.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/ : An announcement on www.ruby-lang.org&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c2f4-jgmc-q2r5</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-58767 — REXML has a DoS condition when parsing malformed XML file</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-58767</link>
      <description>msrc_CVE-2025-58767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-58767</guid>
    </item>
    <item>
      <title>OESA-2025-2655 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2655</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP2: ruby, openEuler:20.03-LTS-SP4: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.(CVE-2025-58767)&lt;/p&gt;
&lt;p&gt;Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer via the use of the `+` operator when combining URIs. An attacker can obtain sensitive user credentials by crafting a URI that, when merged with another, results in the unintended exposure of authentication information.&lt;/p&gt;
&lt;p&gt;**Note:** This vulnerability is a bypass of the fix to CVE-2025-27221.(CVE-2025-61594)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP2: ruby, openEuler:20.03-LTS-SP4: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.(CVE-2025-58767)&lt;/p&gt;
&lt;p&gt;Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer via the use of the `+` operator when combining URIs. An attacker can obtain sensitive user credentials by crafting a URI that, when merged with another, results in the unintended exposure of authentication information.&lt;/p&gt;
&lt;p&gt;**Note:** This vulnerability is a bypass of the fix to CVE-2025-27221.(CVE-2025-61594)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2655</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15828-1 — libruby3_4-3_4-3.4.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15828-1</link>
      <description>&lt;p&gt;libruby3_4-3_4-3.4.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libruby3_4-3_4-3.4.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15828-1</guid>
    </item>
    <item>
      <title>RHSA-2025:23140 — Red Hat Security Advisory: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:23140</link>
      <description>&lt;p&gt;rexml: REXML denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rexml: REXML denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:23140</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58767</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58767</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: ruby3.2, Ubuntu:25.10: ruby3.3, Ubuntu:26.04:LTS: ruby3.3&lt;/p&gt;
&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: ruby3.2, Ubuntu:25.10: ruby3.3, Ubuntu:26.04:LTS: ruby3.3&lt;/p&gt;
&lt;p&gt;REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58767</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2083 — Ruby: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2083</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2083</guid>
    </item>
  </channel>
</rss>
