CVE-2026-33210Disclosure(ruby-lang / json)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ruby-lang json systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-134

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • json

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-21); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
json

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Mentions · 2026-03-29: 2Mentions · 2026-04-16: 1Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-03-29: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-29: 2Technical Details · 2026-04-16: 103-2103-2403-2904-1605-0105-02
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-241
Disclosure1
2026-03-292
Patch2
2026-04-161
Disclosure1
2026-05-011
Disclosure1
2026-05-021
Patch1
Full discourse8 posts
  • White Rabbitx@TheRabbitPy
    Patch

    💎 CVE-2026-33210 (Ruby JSON 2.14-2.19.1): 9.1 format string injection w/ allow_duplicate_key:false—DoS/leak. Fix: 2.19.2+ https://nvd.nist.gov/vuln/detail/CVE-2026-33210

    Post summary

    CVE-2026-33210 is a format string injection in Ruby JSON 2.14-2.19.1 that can cause DoS or data leaks; the issue is fixed in version 2.19.2 and above.

    1000053
    492 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-33210 (json): Ruby JSON has a format string injection vulnerability https://rubysec.com/advisories/CVE-2026-33210/

    Post summary

    RubySec has disclosed a format string injection vulnerability in Ruby JSON (CVE‑2026‑33210). No exploitation or patch details are included in the brief notice.

    0001080
    2.7K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-33210 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/485 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post reports that CVE‑2026‑33210 is no longer present in the latest AWS Lambda base images, suggesting the vulnerability has been addressed or removed, but no patch details or exploit information are provided.

    0000028
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New CRITICAL CVE detected in AWS Lambda 🚨 CVE-2026-33210 impacts json in 1 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/485 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A tweet announces the discovery of a critical CVE-2026-33210 affecting AWS Lambda base images, but offers no PoC, exploit, patch guidance, or detailed technical explanation.

    0000035
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New CRITICAL CVE detected in AWS Lambda 🚨 CVE-2026-33210 impacts json in 1 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/479 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new critical CVE (CVE‑2026‑33210) has been identified impacting JSON in one AWS Lambda base image; details are available via the provided GitHub issue and additional links.

    0000031
    34 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    💥 CVE-2026-33210 (Ruby JSON 2.14.0-2.19.1): Critical 9.1 format string injection—DoS or info leak. Upgrade to fixed versions! https://nvd.nist.gov/vuln/detail/CVE-2026-33210

    Post summary

    The post discloses a severe format string injection vulnerability (CVE-2026-33210) in Ruby JSON and urges users to upgrade to the patched versions.

    0000059
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead t… https://www.cve.org/CVERecord?id=CVE-2026-33210

    Post summary

    The statement delivers an initial disclosure of a format string injection flaw affecting certain Ruby JSON versions, but provides no PoC, exploitation details, or patch information.

    00000121
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or i... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33210

    Post summary

    The message reports a format string injection vulnerability in Ruby JSON (CVE‑2026‑33210) that can cause denial‑of‑service, but provides no PoC, exploit, or patch details.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruby-langjson-ruby-

Explore more