In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Ruby-lang
         Ruby-lang cgi Ruby-lang ruby  | 
|
| CPEs | cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:* cpe:2.3:a:ruby-lang:cgi:0.3.6:*:*:*:*:ruby:*:* cpe:2.3:a:ruby-lang:ruby:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:ruby-lang:ruby:3.2.0:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Ruby-lang
         Ruby-lang cgi Ruby-lang ruby  | 
|
| References | 
         | 
Tue, 06 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | 
Wed, 23 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:8 | |
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux  | 
Sat, 05 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | CGI: ReDoS in CGI::Util#escapeElement. | CGI: ReDoS in CGI::Util#escapeElement | 
Thu, 20 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Tue, 04 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 04 Mar 2025 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | CGI: ReDoS in CGI::Util#escapeElement. | |
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Tue, 04 Mar 2025 00:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method. | |
| Weaknesses | CWE-1333 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-03-03T00:00:00.000Z
Updated: 2025-11-03T21:13:25.250Z
Reserved: 2025-02-20T00:00:00.000Z
Link: CVE-2025-27220
Updated: 2025-03-04T16:39:42.974Z
Status : Modified
Published: 2025-03-04T00:15:31.693
Modified: 2025-11-03T22:18:43.610
Link: CVE-2025-27220