Skip to content

Update rexml gem to solve CVE-2025-58767#9011

Merged
enebo merged 1 commit intojruby:masterfrom
jotamartos:master
Sep 24, 2025
Merged

Update rexml gem to solve CVE-2025-58767#9011
enebo merged 1 commit intojruby:masterfrom
jotamartos:master

Conversation

@jotamartos
Copy link
Contributor

The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations.

GHSA-c2f4-jgmc-q2r5

@enebo enebo added this to the JRuby 10.0.3.0 milestone Sep 24, 2025
@enebo enebo merged commit b024952 into jruby:master Sep 24, 2025
74 of 75 checks passed
@enebo
Copy link
Member

enebo commented Sep 24, 2025

@jotamartos Thanks for the PR!

@headius
Copy link
Member

headius commented Sep 24, 2025

Backport in #9012.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants