CVE-2025-27220
04.03.2025, 00:15
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.Enginsight
Vendor | Product | Version |
---|---|---|
ruby-lang | cgi | 𝑥 < 0.3.5.1 |
ruby-lang | cgi | 0.4.0 ≤ 𝑥 < 0.4.2 |
ruby-lang | cgi | 0.3.6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jruby |
| ||||||||||||
ruby2.3 |
| ||||||||||||
ruby2.5 |
| ||||||||||||
ruby2.7 |
| ||||||||||||
ruby3.0 |
| ||||||||||||
ruby3.2 |
| ||||||||||||
ruby3.3 |
|
Common Weakness Enumeration