CVE-2026-33210
Critical · CVSS 9.1ruby/json — Format String Injection leading to Denial of Service or Information Disclosure
- CVSS
- 9.1
- nvd
- EPSS
- 0.84%
- 54th pct
- KEV
- No
- Class
- oss containerizable
- CWE-134, CWE-134
Description
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
Search profile — drives PoC discovery
Symbols allow_duplicate_keyallow_duplicate_key: falseJSON.parseGHSA-3m6g-2423-7cp3rb_raisejson_parserduplicate_key
Keywords CVE-2026-33210ruby json format string injectionallow_duplicate_key false vulnerabilityGHSA-3m6g-2423-7cp3ruby json CWE-134ruby json duplicate key denial of serviceruby json information disclosureruby json 2.14.0 format string
Versions: >=2.14.0, <2.15.2.1 || >=2.16.0, <2.17.1.2 || >=2.18.0, <2.19.2
Affected packages
| RubyGems | json | 2.14.0 → 2.15.2.1 |
| RubyGems | json | 2.16.0 → 2.17.1.2 |
| RubyGems | json | 2.18.0 → 2.19.2 |
References
- https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3
- https://access.redhat.com/errata/RHSA-2026:20596
- https://access.redhat.com/errata/RHSA-2026:20606
- https://access.redhat.com/security/cve/CVE-2026-33210
- https://bugzilla.redhat.com/show_bug.cgi?id=2449871
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33210.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z