Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33210

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*
Версия от 2.14.0 (включая) до 2.15.2.1 (исключая)
cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*
Версия от 2.16.0 (включая) до 2.17.1.2 (исключая)
cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*
Версия от 2.18.0 (включая) до 2.19.2 (исключая)

EPSS

Процентиль: 54%
0.00838
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-134
CWE-134

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
redhat
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
debian
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to be ...

github
5 месяцев назад

Ruby JSON has a format string injection vulnerability

rocky
около 2 месяцев назад

Important: ruby4.0 security update

EPSS

Процентиль: 54%
0.00838
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-134
CWE-134