CVE-2025-10990

NameCVE-2025-10990
DescriptionA flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2398216
check if RedHat specific incomplete fix for CVE-2024-49761 and for us a NFU

Search for package or bug name: Reporting problems