The following vulnerability was published for ruby3.1.
CVE-2024-49761[0]:
| REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a
| ReDoS vulnerability when it parses an XML that has many digits
| between &# and x...; in a hex numeric character reference (&#x...;).
| This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only
| affected maintained Ruby. The REXML gem 3.3.9 or later include the
| patch to fix the vulnerability.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.