CVE-2026-33210

Aliases:DEBIAN-CVE-2026-33210RHSA-2026:57565CGA-2f9p-xx9h-q4x5CGA-2rch-mcq8-hp2xCGA-4f8m-32r5-rp9vCGA-4vfj-27p8-5m5qCGA-658g-v8qg-c2w7CGA-67hq-m5vm-wqc4CGA-6mf5-v5hw-3c5gCGA-78rx-3p4w-996jCGA-7cwv-8mvr-7r48CGA-97hc-mjwp-93c7CGA-9fxw-r9fh-w325CGA-9rwp-jpf3-rhgjCGA-c7wv-fpf6-vq6vCGA-c8xw-jcjm-9pvmCGA-cc4h-9gmw-v5fmCGA-cr2p-87qq-v3r8CGA-f6hc-h23v-rgwjCGA-h4f3-2hwc-8gx2CGA-h594-vrfq-6j3hCGA-h9j4-9grj-rf85CGA-j53r-wr72-v8mwCGA-jrqg-r336-6pw7CGA-mhhm-r5cp-8687CGA-mprq-m48x-42vjCGA-pv72-w4vv-9jf6CGA-3m62-qp4g-mv95CGA-56xf-4v6v-cc8hCGA-5f88-j3rx-cvg7CGA-6f4r-932r-wmv7CGA-76m9-j9qq-qr45CGA-79gc-2f8c-9x4qCGA-7q4x-jxgg-px2cCGA-8mgc-274g-98vcCGA-cj66-qmq7-rx9rCGA-hmqx-r5gf-939mCGA-qr6f-mpj8-539wCGA-rqp9-35fp-8wjmCGA-rw99-xh2j-279gCGA-vc7r-2gm8-m7fhCGA-w7m9-4ch9-mmv7CGA-wqvr-vpj9-355gCGA-x6hw-8qf7-7625CGA-x6xq-9mwx-jq3wCGA-x856-7529-jjwf
Modified
Published: 20 Mar 2026, 22:57
Last modified:21 Aug 2026, 12:13

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (cve.org)
EPSS Score
0.86% LOW
1% probability +0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Mar 2026, 22:57
Published
Vulnerability first disclosed
21 Aug 2026, 12:13
Last Modified
Vulnerability information updated

Description

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS Metrics

  • v4.0HIGHScore: 8.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Trends

Current EPSS score: 0.86% Percentile: 57%

Techniques & Countermeasures

  • CWE-134Use of Externally-Controlled Format String

    The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Systems

  • chainguardcinc-auditor

    < 7.0.107-r1

  • chainguardgitlab-exporter-18.9

    < 18.9.2-r1

  • chainguardjruby-10.1

    < 0

  • chainguardlogstash-9.2

    < 9.2.7-r1

  • chainguardlogstash-9.2-iamguarded-compat

    < 9.2.7-r1

  • chainguardlogstash-9.2-with-output-opensearch

    < 9.2.7-r1

  • chainguardlogstash-9.3

    < 9.3.2-r1

  • chainguardlogstash-9.3-iamguarded-compat

    < 9.3.2-r1

  • chainguardlogstash-9.3-with-output-opensearch

    < 9.3.2-r1

  • chainguardruby-4.0

    < 4.0.2-r1

  • chainguardruby3.2-fluentd-kubernetes-daemonset-1.16-kinesis

    < 1.16.11.1.0-r1

  • chainguardruby3.2-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.1-r2

  • chainguardruby3.2-rails-8.1

    < 8.1.3-r0

  • chainguardruby3.3-fluentd-kubernetes-daemonset-1.16-kinesis

    < 1.16.11.1.0-r1

  • chainguardruby3.3-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • chainguardruby3.3-rails-8.1

    < 8.1.2.1-r0

  • chainguardruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis

    < 1.16.11.1.0-r1

  • chainguardruby3.4-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • chainguardruby3.4-rails-8.1

    < 8.1.2.1-r0

  • chainguardruby4.0-fluentd-kubernetes-daemonset-1.16-kinesis

    < 1.16.11.1.0-r2

  • chainguardruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • chainguardruby4.0-rails-8.1

    < 8.1.2.1-r0

  • wolficinc-auditor

    < 7.0.107-r1

  • wolfijruby-10.1

    < 0

  • wolfilogstash-9.3

    < 9.3.2-r1

  • wolfilogstash-9.3-iamguarded-compat

    < 9.3.2-r1

  • wolfilogstash-9.3-with-output-opensearch

    < 9.3.2-r1

  • wolfiruby-4.0

    < 4.0.2-r1

  • wolfiruby3.2-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.1-r2

  • wolfiruby3.2-rails-8.1

    < 8.1.3-r0

  • wolfiruby3.3-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • wolfiruby3.3-rails-8.1

    < 8.1.2.1-r0

  • wolfiruby3.4-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • wolfiruby3.4-rails-8.1

    < 8.1.2.1-r0

  • wolfiruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis

    < 1.19.2.1.3-r0

  • wolfiruby4.0-rails-8.1

    < 8.1.2.1-r0

  • debianruby-json

    < 2.19.2+dfsg-1

  • redhatruby4.0

    < 0:4.0.6-37.2.hum1

  • redhatruby4.0-default-gems

    < 0:4.0.6-37.2.hum1

  • ruby-langjson

    ≥ 2.14.0, < 2.15.2.1 | ≥ 2.16.0, < 2.17.1.2 | ≥ 2.18.0, < 2.19.2

  • rubyjson

    ≥ 2.14.0, < 2.15.2.1 | ≥ 2.16.0, < 2.17.1.2 | ≥ 2.18.0, < 2.19.2

References (32)