Loading...
Loading...
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."
August 27, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-3790
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.