CVE-2026-33169Patch(rubyonrails / rails)

LOWCVSS 5.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch rubyonrails rails systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, the interaction between the repeated lookahead group and `gsub!` can produce quadratic time complexity on long digit strings. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rails

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-24)
  • 5 total mentions across 2 days

Affected systems

Products
rails

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-23: 1Mentions · 2026-03-24: 4Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-2303-24
Signal classification3 categories
Patch
240.0%
General
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-231
Patch1
2026-03-244
Disclosure1General2Patch1
Full discourse5 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-33169: Long digit strings can stall Ruby on Rails apps through Active Support’s number_to_delimited (remote, no login). Upgrade to 8.1.2.1 / 8.0.4.1 / 7.2.3.1 asap. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-33169 #Rails #infosec #AppSec

    Post summary

    The advisory warns of a denial‑of‑service flaw in Rails’ number_to_delimited that can be mitigated by upgrading to the latest supported Rails versions.

    01010123
    55 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33169 📊 Severity: 6.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33169 #CVE-2026-33169 #CVE #Medium #CyberSecurity #InfoSec https://t.co/Eakt6WPYbe

    Post summary

    The post announces the existence of CVE-2026-33169 with a medium severity rating, but it lacks technical details, exploit references, or remediation information.

    0000020
    111 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33169 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regu… https://www.cve.org/CVERecord?id=CVE-2026-33169 ----- Traducción: CVE-2026-33169 Act… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-33169 as related to Active Support in Rails but provides no technical or mitigation details.

    0000039
    60 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33169 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regu… https://www.cve.org/CVERecord?id=CVE-2026-33169

    Post summary

    A brief reference to CVE-2026-33169 is provided, with no exploit, patch, or detailed technical information.

    00000183
    56.8K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Ruby on Rails v7.2.3.1 がリリースされました。 📦 種別: patch ✨ 主な変更点: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) ⚠️ 破壊的変更: • `DiskService#delete_prefixed`の変更により、既存のグロブメタ文字展開に依存するコードは動作しなくなります。 🔧 重要な修正: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) #GitHub #Release #Ruby on Rails

    Post summary

    Ruby on Rails v7.2.3.1 patch release addressing several CVEs with detailed mitigation changes.

    0000036
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprubyonrailsrails---

Explore more