Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33210

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

A flaw was found in Ruby JSON. This vulnerability, a format string injection, allows a remote attacker to cause a denial of service (DoS) or disclose sensitive information. The flaw occurs when processing specially crafted user-supplied documents with the allow_duplicate_key: false parsing option enabled.

Отчет

A format string injection flaw was identified in Ruby JSON. This vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information when processing specially crafted user-supplied documents with the allow_duplicate_key: false parsing option enabled. Red Hat Enterprise Linux 9.9 (ruby:4.0/ruby), Red Hat Enterprise Linux 10.3 (ruby4.0), and Insights (cloudservices/compliance-backend) are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp20/backendNot affected
Red Hat 3scale API Management Platform 23scale-amp20/systemNot affected
Red Hat 3scale API Management Platform 23scale-amp21/backendNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=2449871ruby/json: Ruby JSON: Denial of Service or Information Disclosure via format string injection

EPSS

Процентиль: 54%
0.00838
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
nvd
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
debian
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to be ...

github
5 месяцев назад

Ruby JSON has a format string injection vulnerability

rocky
около 2 месяцев назад

Important: ruby4.0 security update

EPSS

Процентиль: 54%
0.00838
Низкий

9.1 Critical

CVSS3