CVE-2026-33210 Details
Description
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
A format string injection vulnerability has been identified in Ruby JSON versions 2.14.0 prior to 2.15.2.1, 2.17.1.2, and 2.19.2. This vulnerability can lead to denial-of-service attacks or information disclosure when the 'allow_duplicate_key: false' parsing option is used with user-supplied documents. The issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
Users can upgrade to Ruby JSON versions 2.15.2.1, 2.17.1.2, or 2.19.2 to address this vulnerability. If an upgrade is not possible, the issue can be avoided by not using the 'allow_duplicate_key: false' parsing option.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:20596 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:20606 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:57565 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-33210 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2449871 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33210.json | redhat-SADP | |
| https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | redhat-SADP |
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ruby-lang json | >= 2.14.0, < 2.15.2.1 >= 2.16.0, < 2.17.1.2 >= 2.18.0, < 2.19.2 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 21, 2026 | CVE Modified | redhat-SADP |
| Aug 19, 2026 | CVE Modified | redhat-SADP |
| Jul 21, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 27, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |