ruby is vulnerable to XML injection. The vulnerability exists due to REXML gem creating a wrong XML document whose structure is different from the original one.
lists.fedoraproject.org/archives/list/[email protected]/message/WTVFTLFVCSUE5CXHINJEUCKSHU4SWDMT/
secdb.alpinelinux.org/v3.10/main.yaml
secdb.alpinelinux.org/v3.11/main.yaml
secdb.alpinelinux.org/v3.12/main.yaml
secdb.alpinelinux.org/v3.13/main.yaml
security.netapp.com/advisory/ntap-20210528-0003/
www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-vulnerability-in-rexml-cve-2021-28965/