/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-rjx5-mh73-46fx

Published

Last updated

https://images.chainguard.dev/security/CGA-rjx5-mh73-46fx
Package

ruby-3.0

RepositoryWolfi
Latest Update
Fix not planned
Aliases
  • CVE-2025-27220
  • GHSA-mhwm-jh88-3gjf

Severity

Unknown

Summary

CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement

Description

There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem.

Details

The regular expression used in CGI::Util#escapeElement is vulnerable to ReDoS. The crafted input could lead to a high CPU consumption.

This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later.

Affected versions

cgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1.

Credits

Thanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs