CVE-2026-33176

Aliases:DEBIAN-CVE-2026-33176CGA-3h9x-322g-86ghCGA-66r4-9qq3-4gghCGA-79w2-cg4j-r8q9CGA-7hfr-3f5g-7jxgCGA-crmw-4xwp-v38gCGA-f25v-5c4x-7jmvCGA-299c-6cx2-6mhpCGA-2hc3-9g3j-xvrgCGA-2m94-rjc9-9pp3CGA-322v-hcrg-3qfgCGA-38hh-v2pg-852qCGA-4f6h-9664-765jCGA-4h6q-4gf2-fw82CGA-4wcw-wg76-76vfCGA-696h-932r-p9vgCGA-6qrc-vr3q-rjcvCGA-6w2f-mf2w-hwg9CGA-78h3-r4vr-jxjxCGA-78j6-c8mv-frjcCGA-7g9g-8hmh-9c5mCGA-7jpv-5m8m-h4frCGA-7p6x-jh9x-gr38CGA-7vp3-xvgj-445vCGA-87gx-m557-q3gxCGA-895w-wmj5-vg6jCGA-8wg6-pjq7-qv8cCGA-9357-4xp6-772cCGA-9vm6-qjqw-2r9vCGA-cq83-whp7-r9mqCGA-cxm2-847g-7rx4CGA-g342-p8jj-8x49CGA-gh8c-36vf-mm36CGA-gmjv-f8qv-vj88CGA-h8jv-x2m7-8c54CGA-h8q3-h7mh-hq5jCGA-hf47-x65j-f8wvCGA-hmfh-g66h-vv3rCGA-jpcc-gwm2-q4f9CGA-mh8f-cfxc-h7q3CGA-p595-qr46-w9f5CGA-p85q-497h-cp36CGA-pr8p-rgx6-875gCGA-q3x9-2q56-f5m6CGA-r28p-4935-rg37CGA-rf98-33x3-wq9qCGA-rxcc-xjq8-vm47CGA-vmm7-rmr3-x64rCGA-w5p2-9q6v-5h64CGA-w87j-28rc-xvq9CGA-w8h9-5fcf-6fvmCGA-w8hv-39p4-5c94CGA-wf6g-27r6-79c9CGA-wgvh-4969-2wvpCGA-wpp6-8hcc-2mqjCGA-xcjp-f966-q9cmCGA-xp3v-8gw4-rc9jCGA-xrp4-7923-q86xCGA-xvq5-9269-jfq9
Analyzed
Published: 23 Mar 2026, 23:29
Last modified:24 Mar 2026, 18:42

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.84% LOW
1% probability +0.23%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Mar 2026, 23:29
Published
Vulnerability first disclosed
24 Mar 2026, 18:42
Last Modified
Vulnerability information updated

Description

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS Metrics

  • v4.0MEDIUMScore: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
  • v4.0MEDIUMScore: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.84% Percentile: 56%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardcinc-auditor

    < 7.0.107-r1

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    < 18.10.3-r1

  • chainguardgitlab-rails-ce-18.2

    all

  • chainguardgitlab-rails-ce-18.3

    all

  • chainguardgitlab-rails-ce-18.4

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    < 18.8.11-r4

  • chainguardgitlab-rails-ce-18.9

    < 18.9.5-r0

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    < 18.10.3-r0

  • chainguardgitlab-rails-ce-fips-18.2

    all

  • chainguardgitlab-rails-ce-fips-18.3

    all

  • chainguardgitlab-rails-ce-fips-18.4

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    < 18.9.5-r0

  • chainguardkube-fluentd-operator

    < 1.18.2-r60

  • chainguardkube-logging-operator-fluentd-outputs

    < 6.4.0-r9

  • chainguardruby3.2-rails-7.1

    all

  • chainguardruby3.2-rails-8.1

    < 8.1.3-r0

  • chainguardruby3.3-rails-7.1

    all

  • chainguardruby3.4-rails-7.1

    all

  • chainguardruby3.4-rails-8.0

    < 8.0.5-r0

  • chainguardruby4.0-rails-7.1

    all

  • wolficinc-auditor

    < 7.0.107-r1

  • wolfikube-fluentd-operator

    < 1.18.2-r60

  • wolfikube-logging-operator-fluentd-outputs

    < 6.4.0-r9

  • wolfiruby3.2-rails-8.1

    < 8.1.3-r0

  • debianrails

    all | all | all | < 2:7.2.3.1+dfsg-1

  • railsactivesupport

    ≥ 8.1.0.beta1, < 8.1.2.1 | ≥ 8.0.0.beta1, < 8.0.4.1 | < 7.2.3.1

  • rubyonrailsrails

    < 7.2.3.1 | ≥ 8.0.0, < 8.0.4.1 | ≥ 8.1.0, < 8.1.2.1

References (10)