GHSA-c2f4-jgmc-q2r5 · Severity: low · Ecosystem: rubygems — REXML has DoS condition when parsing malformed XML file
REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.
Conclusion & alert: CVE-2025-58767 is rated Low Risk (10.4/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-23 | 0.01% | 0.05% | +0.04% |
| 2 | 2025-09-18 | — | 0.01% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.2 | 4.0 | LOW |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
GHSA-c2f4-jgmc-q2r5 · Severity: low · Ecosystem: rubygems — REXML has DoS condition when parsing malformed XML file
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-58767: 1 source package rows (ruby-rexml); 13 state rows across 6 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, 3.23-main, edge-main); fixed 2, open 11. | https://security.alpinelinux.org/vuln/CVE-2025-58767 |
debian
|
unimportant | CVE-2025-58767 unimportant priority: Debian including 3 source packages (ruby2.7, ruby3.1, ruby3.3), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 4, resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-58767 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-58767 |
suse
|
low | CVE-2025-58767 severity low: SUSE including 70 source package names (libruby2_1-2_1, libruby3_4-3_4-3.4.8-1.1, …), 131 product×package rows across 34 product lines (SLES-LTSS-TERADATA 15 SP2, SUSE Liberty Linux 8, … (34 product lines)): Known Not Affected 67, Fixed 64. | https://www.suse.com/security/cve/CVE-2025-58767/ |
ubuntu
|
low | CVE-2025-58767 low priority: Ubuntu including 7 source packages (jruby, ruby2.3, …), 42 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): DNE 21, not-affected 8, needed 6, needs-triage 6, ignored 1. | https://ubuntu.com/security/CVE-2025-58767 |