In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
2025-03-04T00:15:31.693
2025-03-05T14:58:14.463
Analyzed
CVSSv3.1: 4.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ruby-lang | cgi | < 0.3.5.1 | Yes |
Application | ruby-lang | cgi | < 0.4.2 | Yes |
Application | ruby-lang | cgi | 0.3.6 | Yes |
Application | ruby-lang | ruby | 3.1.0 | No |
Application | ruby-lang | ruby | 3.2.0 | No |