Vulnerability Description
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Cgi | < 0.3.5.1 |
| Ruby-Lang | Ruby | 3.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.Third Party Advisory
- https://hackerone.com/reports/2890322Permissions Required
- https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html
FAQ
What is CVE-2025-27220?
CVE-2025-27220 is a vulnerability with a CVSS score of 4.0 (MEDIUM). In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
How severe is CVE-2025-27220?
CVE-2025-27220 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27220?
Check the references section above for vendor advisories and patch information. Affected products include: Ruby-Lang Cgi, Ruby-Lang Ruby.