PT-2026-109865 · Decimal · Decimal

·

CVE-2026-97853

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions decimal versions 0.1.0 through 3.1.1
Description A memory allocation issue exists in the Decimal.round/3 function that allows for a Denial of Service. The function builds the full result for the requested number of decimal places before applying context precision, causing memory consumption to grow based on the places argument rather than the result size. For positive places, the software appends zero digits to the coefficient as a charlist; for negative places, it builds a charlist of zero digits. A large value, such as -50,000,000, can allocate approximately 5.5 GB of memory, potentially exhausting available resources and causing the BEAM VM to be killed. In older releases, this issue manifests as high CPU consumption due to looping once per decimal place. Applications are exposed if they pass user-supplied values to Decimal.round/2 or Decimal.round/3 without proper bounding.
Recommendations Update decimal to version 3.1.2 or later. As a temporary workaround, bound the places argument before calling Decimal.round/2 or Decimal.round/3, for example, restricting it to a range such as -34..34 or to the specific scales supported by the application.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97853
GHSA-6C27-994X-C52F

Affected Products

Decimal