CVE-2026-33210
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Beschreibung
Ruby JSON ist eine JSON-Implementierung für Ruby. Von Version 2.14.0 bis vor den Versionen 2.15.2.1, 2.17.1.2 und 2.19.2 kann ein Formatstring-Injektions-Schwachstellen zu Denial-of-Service-Angriffen oder Informationslecks führen, wenn die Option allow_duplicate_key: false zum Parsen von benutzerbereitgestellten Dokumenten verwendet wird. Dieses Problem wurde in den Versionen 2.15.2.1, 2.17.1.2 und 2.19.2 behoben.
Metriken
Weakness-Klassen (CWE)
CWE-134Base
Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-21 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:57565
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift (+38) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images (+38)
- CVE Modified2026-08-19 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift (+37) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift (+38)
- CVE Modified2026-07-21 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift (+38) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift (+37)
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
ruby-lang
json2.14.0 – 2.15.2.1
ruby-lang
json2.16.0 – 2.17.1.2
ruby-lang
json2.18.0 – 2.19.2
Quellen & Referenzen
- https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3web
- https://nvd.nist.gov/vuln/detail/CVE-2026-33210advisory
- https://github.com/ruby/jsonpackage
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2026-33210.ymlweb
- https://access.redhat.com/security/cve/CVE-2026-33210vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2449871issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33210.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:20606vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:20596vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57565vendor-advisoryx_refsource_REDHAT