CVE-2024-35176 | rexml Gem up to 3.2.6 on Ruby XML Data Parser attribute resource consumption (GHSA-vg3r-rm7w-2xgh / Nessus ID 210110)
A vulnerability labeled as problematic has been found in rexml Gem up to 3.2.6 on Ruby. Affected by this vulnerability is an unknown functionality of the component XML Data Parser. Such manipulation of the argument attribute with the input < leads to resource consumption.
This vulnerability is listed as CVE-2024-35176. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.