A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.

Project Subscriptions

Vendors Products
Rhel Satellite Client Subscribe
Satellite Subscribe
Satellite Capsule Subscribe
Satellite Utils Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

History

Fri, 27 Feb 2026 13:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
Title rexml: incomplete fix for CVE-2024-49761 Rexml: rexml: denial of service via inefficient regex parsing
First Time appeared Redhat
Redhat rhel Satellite Client
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
CPEs cpe:/a:redhat:rhel_satellite_client:6::el8
cpe:/a:redhat:rhel_satellite_client:6::el9
cpe:/a:redhat:satellite:6.16::el8
cpe:/a:redhat:satellite:6.16::el9
cpe:/a:redhat:satellite:6.17::el9
cpe:/a:redhat:satellite_capsule:6.16::el8
cpe:/a:redhat:satellite_capsule:6.16::el9
cpe:/a:redhat:satellite_capsule:6.17::el9
cpe:/a:redhat:satellite_utils:6.16::el8
cpe:/a:redhat:satellite_utils:6.16::el9
cpe:/a:redhat:satellite_utils:6.17::el9
Vendors & Products Redhat
Redhat rhel Satellite Client
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References

Fri, 26 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title rexml: incomplete fix for CVE-2024-49761
Weaknesses CWE-1333
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-27T13:32:02.309Z

Reserved: 2025-09-25T17:30:55.821Z

Link: CVE-2025-10990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-27T14:16:27.567

Modified: 2026-02-27T14:16:27.567

Link: CVE-2025-10990

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-09-25T00:00:00Z

Links: CVE-2025-10990 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses