PT-2026-26298 · Ruby+1 · Json+2

·

CVE-2026-33210

·

Published

2026-03-19

·

Updated

2026-08-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ruby JSON versions 2.14.0 through 2.15.2.0 Ruby JSON versions 2.17.0 through 2.17.1.1 Ruby JSON versions 2.19.0 through 2.19.1
Description A format string injection flaw exists when processing specially crafted user-supplied documents while the allow duplicate key: false parsing option is enabled. This can allow a remote attacker to cause a denial of service (DoS) or disclose sensitive information.
Recommendations Update Ruby JSON to version 2.15.2.1. Update Ruby JSON to version 2.17.1.2. Update Ruby JSON to version 2.19.2. As a temporary workaround, avoid using the allow duplicate key: false parsing option.

Exploit

Fix

DoS

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:20596
ALSA-2026:20606
CLEANSTART-2026-CQ39708
CLEANSTART-2026-DV49899
CLEANSTART-2026-GE08280
CLEANSTART-2026-OQ84658
CLEANSTART-2026-RZ30606
CVE-2026-33210
GHSA-3M6G-2423-7CP3
RHSA-2026:20596
RHSA-2026:20606
RHSA-2026:57565

Affected Products

Json
Rocky Linux
Ruby