Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-43398


REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.


Published

2024-08-22T15:15:16.440

Last Modified

2025-09-19T15:51:22.903

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-776

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ruby-lang rexml < 3.3.6 Yes
Operating System netapp bootstrap_os - Yes
Hardware netapp hci_compute_node - No

References