Loading...
Loading...
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
December 12, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-1812
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.