In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4063 https://access.redhat.com/errata/RHSA-2025:4063
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:4487 https://access.redhat.com/errata/RHSA-2025:4487
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:4488 https://access.redhat.com/errata/RHSA-2025:4488