CVE-2026-33176
Vulnerability Summary
Timeline
Description
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
- v4.0•MEDIUM•Score: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.84%• Percentile: 56%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- chainguard•cinc-auditor
< 7.0.107-r1
- chainguard•gitlab-rails-ce-18.1
all
- chainguard•gitlab-rails-ce-18.10
< 18.10.3-r1
- chainguard•gitlab-rails-ce-18.2
all
- chainguard•gitlab-rails-ce-18.3
all
- chainguard•gitlab-rails-ce-18.4
all
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
< 18.8.11-r4
- chainguard•gitlab-rails-ce-18.9
< 18.9.5-r0
- chainguard•gitlab-rails-ce-fips-18.1
all
- chainguard•gitlab-rails-ce-fips-18.10
< 18.10.3-r0
- chainguard•gitlab-rails-ce-fips-18.2
all
- chainguard•gitlab-rails-ce-fips-18.3
all
- chainguard•gitlab-rails-ce-fips-18.4
all
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
< 18.9.5-r0
- chainguard•kube-fluentd-operator
< 1.18.2-r60
- chainguard•kube-logging-operator-fluentd-outputs
< 6.4.0-r9
- chainguard•ruby3.2-rails-7.1
all
- chainguard•ruby3.2-rails-8.1
< 8.1.3-r0
- chainguard•ruby3.3-rails-7.1
all
- chainguard•ruby3.4-rails-7.1
all
- chainguard•ruby3.4-rails-8.0
< 8.0.5-r0
- chainguard•ruby4.0-rails-7.1
all
- wolfi•cinc-auditor
< 7.0.107-r1
- wolfi•kube-fluentd-operator
< 1.18.2-r60
- wolfi•kube-logging-operator-fluentd-outputs
< 6.4.0-r9
- wolfi•ruby3.2-rails-8.1
< 8.1.3-r0
- debian•rails
all | all | all | < 2:7.2.3.1+dfsg-1
- rails•activesupport
≥ 8.1.0.beta1, < 8.1.2.1 | ≥ 8.0.0.beta1, < 8.0.4.1 | < 7.2.3.1
- rubyonrails•rails
< 7.2.3.1 | ≥ 8.0.0, < 8.0.4.1 | ≥ 8.1.0, < 8.1.2.1
References (10)
- https://github.com/rails/rails/security/advisories/GHSA-2j26-frm8-cmj9
- https://github.com/rails/rails/commit/19dbab51ca086a657bb86458042bc44314916bcb
- https://github.com/rails/rails/commit/ebd6be18120d1136511eb516338e27af25ac0a1a
- https://github.com/rails/rails/commit/ee2c59e730e5b8faed502cd2c573109df093f856
- https://github.com/rails/rails/releases/tag/v7.2.3.1
- https://github.com/rails/rails/releases/tag/v8.0.4.1
- https://github.com/rails/rails/releases/tag/v8.1.2.1
- https://security-tracker.debian.org/tracker/CVE-2026-33176
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33176.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-33176