CVE-2026-33306Disclosure(bcrypt-ruby_project / bcrypt-ruby)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bcrypt-ruby_project bcrypt-ruby systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes the key-strengthening round count as a signed 32-bit integer. When `cost=31` (the maximum allowed by the gem), signed integer overflow causes the round count to become negative, and the strengthening loop executes **zero iterations**. This collapses bcrypt from 2^31 rounds of exponential key-strengthening to effectively constant-time computation — only the initial EksBlowfish key setup and final 64x encryption phase remain. The resulting hash looks valid (`$2a$31$...`) and verifies correctly via `checkpw`, making the weakness invisible to the application. This issue is triggered only when cost=31 is used or when verifying a `$2a$31$` hash. This problem has been fixed in version 3.1.22. As a workaround, set the cost to something less than 31.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bcrypt-ruby

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
bcrypt-ruby

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-18: 1Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 103-1803-2403-25
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-181
Patch1
2026-03-242
Disclosure2
2026-03-251
General1
Full discourse4 posts
  • JRuby Dev Team@jruby
    Patch

    Today we were informed of a low-severity vulnerability in the bcrypt-ruby gem. We worked with the maintainers to arrange a fix. Upgrading is recommended. CVE-2026-33306: Integer Overflow Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby https://github.com/bcrypt-ruby/bcrypt-ruby/security/advisories/GHSA-f27w-vcwj-c954

    Post summary

    A low‑severity integer overflow flaw was disclosed in bcrypt‑ruby; maintainers have released a fix, and upgrading is advised.

    00041218
    5.5K followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-33306 (bcrypt): bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby https://rubysec.com/advisories/CVE-2026-33306/

    Post summary

    RubySec reports that bcrypt-ruby has an integer overflow in JRuby leading to zero key‑strengthening iterations, but no PoC, exploit code, or patch is referenced.

    0001086
    2.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33306 📊 Severity: 4.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33306 #CVE-2026-33306 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/ev4utBjSFE

    Post summary

    The tweet simply announces CVE-2026-33306 with its severity and risk rating but lacks detailed technical, PoC, or exploitation information.

    0000030
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33306 bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for … https://www.cve.org/CVERecord?id=CVE-2026-33306

    Post summary

    The text announces CVE‑2026‑33306 as an integer‑overflow flaw in bcrypt‑ruby (pre‑3.1.22) and links to the CVE record, but provides no proof of exploitation, a PoC, or patch details.

    00000155
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbcrypt-ruby_projectbcrypt-ruby-ruby-

Explore more