
🚨 CVE-2026-33169: Long digit strings can stall Ruby on Rails apps through Active Support’s number_to_delimited (remote, no login). Upgrade to 8.1.2.1 / 8.0.4.1 / 7.2.3.1 asap. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-33169 #Rails #infosec #AppSec
Post summary
The advisory warns of a denial‑of‑service flaw in Rails’ number_to_delimited that can be mitigated by upgrading to the latest supported Rails versions.




