Vulnerabilities > CVE-2025-27220 - Unspecified vulnerability in Ruby-Lang CGI 0.3.6

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
ruby-lang

Summary

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

Vulnerable Configurations

Part Description Count
Application
Ruby-Lang
4