{"id":"GHSA-3m6g-2423-7cp3","summary":"Ruby JSON has a format string injection vulnerability","details":"### Impact\n\nA format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the `allow_duplicate_key: false` parsing option is used to parse user supplied documents. \n\nThis option isn't the default, if you didn't opt-in to use it, you are not impacted.\n\n### Patches\n\nPatched in `2.19.2`.\n\n### Workarounds\n\nThe issue can be avoided by not using the `allow_duplicate_key: false` parsing option.","aliases":["CVE-2026-33210"],"modified":"2026-07-17T21:09:12.680608647Z","published":"2026-03-19T12:45:53Z","database_specific":{"cwe_ids":["CWE-134"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-19T12:45:53Z","nvd_published_at":"2026-03-20T23:16:46Z"},"references":[{"type":"WEB","url":"https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33210"},{"type":"PACKAGE","url":"https://github.com/ruby/json"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2026-33210.yml"}],"affected":[{"package":{"name":"json","ecosystem":"RubyGems","purl":"pkg:gem/json"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.18.0"},{"fixed":"2.19.2"}]}],"versions":["2.18.0","2.18.1","2.19.0","2.19.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3m6g-2423-7cp3/GHSA-3m6g-2423-7cp3.json"}},{"package":{"name":"json","ecosystem":"RubyGems","purl":"pkg:gem/json"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.16.0"},{"fixed":"2.17.1.2"}]}],"versions":["2.16.0","2.17.0","2.17.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3m6g-2423-7cp3/GHSA-3m6g-2423-7cp3.json"}},{"package":{"name":"json","ecosystem":"RubyGems","purl":"pkg:gem/json"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.14.0"},{"fixed":"2.15.2.1"}]}],"versions":["2.14.0","2.14.1","2.15.0","2.15.1","2.15.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3m6g-2423-7cp3/GHSA-3m6g-2423-7cp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"}]}