CVE-2025-10990: Rexml: rexml: denial of service via inefficient regex parsing
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is the result of an incomplete fix for CVE-2024-49761.
Other sources
an incomplete fix was released for Red Hat Satellite Client for CVE-2024-49761
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10990?
CVE-2025-10990 is classified with a high severity level due to its incomplete fix related to a previous vulnerability.
How do I fix CVE-2025-10990?
To fix CVE-2025-10990, you should apply the latest patches released by Red Hat for the Satellite Client.
Which software is affected by CVE-2025-10990?
CVE-2025-10990 affects the Red Hat Satellite Client software.
What vulnerability did CVE-2025-10990 address?
CVE-2025-10990 addresses an incomplete fix for the earlier CVE-2024-49761 vulnerability.
How can I confirm if my system is vulnerable to CVE-2025-10990?
You can confirm vulnerability to CVE-2025-10990 by checking your current version of Red Hat Satellite Client against the latest security advisories.