{"id":"CVE-2026-33210","aliases":["GHSA-3m6g-2423-7cp3"],"url":"https://o3.security/vulnerability/CVE-2026-33210","summary":"Ruby JSON has a format string injection vulnerability","details":"Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.","published":"2026-03-20T22:57:08.758Z","modified":"2026-08-24T03:59:11.755004Z","cvss":null,"epss":{"score":0.00857,"percentile":0.56708,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"json","fixedVersion":"2.19.2"},{"ecosystem":"RubyGems","name":"json","fixedVersion":"2.17.1.2"},{"ecosystem":"RubyGems","name":"json","fixedVersion":"2.15.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33210.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20596"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20606"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57565"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-33210"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33210.json"},{"type":"ADVISORY","url":"https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33210"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2449871"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T03:59:11.755004Z"}}