{"api_version":"v1","generated_at":"2026-10-05T01:35:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-ruby-rexml-6d0a19cdd11e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/rexml","name":"rexml","next_cursor":null,"observations":[{"affected":">= 3.3.3, < 3.4.2","affected_versions_present":true,"cve_id":"CVE-2025-58767","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58767","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-17T17:54:00.334Z","patch_url":"https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23","primary_source":"","published":"2025-09-17T17:45:58.118Z"},{"affected":"< 3.3.9","affected_versions_present":true,"cve_id":"CVE-2024-49761","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-49761","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T20:41:10.439Z","patch_url":"https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f","primary_source":"","published":"2024-10-28T14:10:23.212Z"},{"affected":"< 3.3.6","affected_versions_present":true,"cve_id":"CVE-2024-43398","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43398","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T20:38:50.990Z","patch_url":"","primary_source":"","published":"2024-08-22T14:14:03.588Z"},{"affected":"< 3.3.3","affected_versions_present":true,"cve_id":"CVE-2024-41946","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41946","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T20:38:34.071Z","patch_url":"https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368","primary_source":"","published":"2024-08-01T14:22:14.014Z"},{"affected":"< 3.3.3","affected_versions_present":true,"cve_id":"CVE-2024-41123","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41123","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T20:38:32.688Z","patch_url":"","primary_source":"","published":"2024-08-01T14:18:43.611Z"},{"affected":"< 3.3.2","affected_versions_present":true,"cve_id":"CVE-2024-39908","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-39908","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T20:38:21.548Z","patch_url":"","primary_source":"","published":"2024-07-16T17:28:07.372Z"},{"affected":"< 3.2.7","affected_versions_present":true,"cve_id":"CVE-2024-35176","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35176","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T20:37:32.949Z","patch_url":"https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb","primary_source":"","published":"2024-05-16T15:13:25.100Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"ruby"}}
