In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.3.5.1"
},
{
"introduced": "0.4.0"
},
{
"fixed": "0.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.6"
}
]
}