The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)

Source: Mageia 2025-0001: ruby Security Advisory Updates