CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-33210

Critical · CVSS 9.1

ruby/json — Format String Injection leading to Denial of Service or Information Disclosure

CVSS
9.1
nvd
EPSS
0.84%
54th pct
KEV
No
Class
oss containerizable
CWE-134, CWE-134

Description

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

Search profile — drives PoC discovery

Symbols allow_duplicate_keyallow_duplicate_key: falseJSON.parseGHSA-3m6g-2423-7cp3rb_raisejson_parserduplicate_key
Keywords CVE-2026-33210ruby json format string injectionallow_duplicate_key false vulnerabilityGHSA-3m6g-2423-7cp3ruby json CWE-134ruby json duplicate key denial of serviceruby json information disclosureruby json 2.14.0 format string
Versions: >=2.14.0, <2.15.2.1 || >=2.16.0, <2.17.1.2 || >=2.18.0, <2.19.2

Affected packages

RubyGems json 2.14.0 → 2.15.2.1
RubyGems json 2.16.0 → 2.17.1.2
RubyGems json 2.18.0 → 2.19.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z