← Vulnerability feed

Vulnerability record · CVE-2008-3790 · published 27 August 2008

CVE-2008-3790: Ruby-lang ruby improper input validation vulnerability

Ruby Lang · Ruby

The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."

5.0 CVSS 2.0 Medium EPSS 15% · top 3.4% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
70References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://groups.google.com/group/comp.lang.ruby/browse_thread/thread/19f69e8a081fc0d1/e138e014b74352ca
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/31602
http://secunia.com/advisories/32165
http://secunia.com/advisories/32219
http://secunia.com/advisories/32255
http://secunia.com/advisories/32256
http://secunia.com/advisories/32371
http://secunia.com/advisories/33178
http://secunia.com/advisories/33185
http://secunia.com/advisories/35074
http://security.gentoo.org/glsa/glsa-200812-17.xml
http://support.apple.com/kb/HT3549
http://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
http://weblog.rubyonrails.org/2008/9/3/rails-2-0-4-maintenance-release
http://www.debian.org/security/2008/dsa-1651
http://www.debian.org/security/2008/dsa-1652
http://www.openwall.com/lists/oss-security/2008/08/25/4
http://www.openwall.com/lists/oss-security/2008/08/26/1
http://www.openwall.com/lists/oss-security/2008/08/26/4
http://www.redhat.com/support/errata/RHSA-2008-0897.html
http://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml/ ExploitPatch
http://www.ruby-lang.org/security/20080823rexml/rexml-expansion-fix.rb Patch
http://www.securityfocus.com/bid/30802
http://www.securitytracker.com/id?1020735
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2008/2428
http://www.vupen.com/english/advisories/2008/2483
http://www.vupen.com/english/advisories/2009/1297
https://exchange.xforce.ibmcloud.com/vulnerabilities/44628
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10393
https://usn.ubuntu.com/651-1/
https://usn.ubuntu.com/691-1/
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00259.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00299.html
http://groups.google.com/group/comp.lang.ruby/browse_thread/thread/19f69e8a081fc0d1/e138e014b74352ca
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/31602
http://secunia.com/advisories/32165
http://secunia.com/advisories/32219

Track CVE-2008-3790 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4124Ruby-lang ruby memory buffer overflow vulnerabilityHeap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute a…EPSS 3.9%10.0CVE-2008-2662Ruby-lang ruby vulnerabilityMultiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…EPSS 4.3%10.0CVE-2008-2663Ruby-lang ruby integer overflow vulnerabilityMultiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before…EPSS 4.5%9.8CVE-2016-2338Ruby-lang ruby out-of-bounds write vulnerabilityAn exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he…EPSS 4.7%9.8CVE-2022-28738Ruby-lang ruby double free vulnerabilityA double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste…EPSS 2.9%9.8CVE-2011-4121Ruby-lang ruby inadequate encryption strength vulnerabilityThe OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private…EPSS 2.5%9.8CVE-2018-16395Ruby-lang openssl vulnerabilityAn issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When tw…EPSS 11%9.8CVE-2017-17790Ruby-lang ruby injection vulnerabilityThe lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2008-3790), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.