Описание
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-08-17 |
| esm-apps-legacy/xenial | deferred | 2026-08-17 |
| esm-apps/bionic | deferred | 2026-08-17 |
| esm-apps/focal | deferred | 2026-08-17 |
| esm-apps/noble | deferred | 2026-08-17 |
| esm-apps/resolute | deferred | 2026-08-17 |
| esm-apps/xenial | ignored | end of ESM support, was deferred [2026-08-17] |
| esm-infra-legacy/trusty | deferred | 2026-08-17 |
| jammy | DNE | |
| noble | deferred | 2026-08-17 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/xenial | deferred | 2026-08-17 |
| esm-infra/xenial | ignored | end of ESM support, was deferred [2026-08-17] |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/bionic | deferred | 2026-08-17 |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/focal | deferred | 2026-08-17 |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| jammy | deferred | 2026-08-17 |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| jammy | DNE | |
| noble | deferred | 2026-08-17 |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-08-17 |
| jammy | DNE | |
| noble | DNE | |
| questing | ignored | end of life, was deferred [2026-08-17] |
| resolute | deferred | 2026-08-17 |
| upstream | needs-triage |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
A flaw was found in REXML. A remote attacker could exploit inefficient ...
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
7.5 High
CVSS3