CVEFinder.io

CVE-2024-49761

âš ī¸ high
🔍 Scan for this CVE
Summary

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS Score
7.5
High
EPSS Score
1.2
Exploit Probability
Published Date
2024-10-28
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.9% of all 329,456 vulnerabilities in our database.

#102,448
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Oct 28, 2024
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-11-03
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 2

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-58767 đŸ”ļ medium 5.3 0.0 REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing... 2025-09-17
CVE-2025-27820 âš ī¸ high 7.5 0.1 A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na... 2025-04-24
CVE-2025-0167 â„šī¸ low 3.4 0.2 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used fo... 2025-02-05
CVE-2024-52533 ⛔ critical 9.8 3.1 gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CON... 2024-11-11
CVE-2024-38286 âš ī¸ high 8.6 0.4 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ... 2024-11-07
CVE-2024-47554 đŸ”ļ medium 4.3 0.2 Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c... 2024-10-03
These CVEs affect the same products