CVE-2026-33176
published 2026-03-24CVE-2026-33176: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.61%
45.5th percentile
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | — | — |
| rails | activesupport | < 7.2.3.1 | 7.2.3.1 |
| rails | activesupport | — | — |
| rails | activesupport | — | — |
| rails | activesupport | >= 0 < 7.2.3.1 | 7.2.3.1 |
| rails | activesupport | >= 8.0.0.beta1 < 8.0.4.1 | 8.0.4.1 |
| rails | activesupport | >= 8.1.0.beta1 < 8.1.2.1 | 8.1.2.1 |
| rubyonrails | rails | < 7.2.3.1 | 7.2.3.1 |
| rubyonrails | rails | >= 8.0.0 < 8.0.4.1 | 8.0.4.1 |
| rubyonrails | rails | >= 8.1.0 < 8.1.2.1 | 8.1.2.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.6MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-33176: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework
osv·2026-03-24·CVSS 6.6
CVE-2026-33176 [MEDIUM] CVE-2026-33176: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
GHSA
Rails Active Support has a possible DoS vulnerability in its number helpers
ghsa·2026-03-23
CVE-2026-33176 [MEDIUM] CWE-400 Rails Active Support has a possible DoS vulnerability in its number helpers
Rails Active Support has a possible DoS vulnerability in its number helpers
### Impact
Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which when converted to a string could be expanded into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability.
### Releases
The fixed releases are available at the normal locations.
### Credit
https://hackerone.com/manun
OSV
Rails Active Support has a possible DoS vulnerability in its number helpers
osv·2026-03-23
CVE-2026-33176 [MEDIUM] Rails Active Support has a possible DoS vulnerability in its number helpers
Rails Active Support has a possible DoS vulnerability in its number helpers
### Impact
Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which when converted to a string could be expanded into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability.
### Releases
The fixed releases are available at the normal locations.
### Credit
https://hackerone.com/manun
Red Hat
Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
vendor_redhat·2026-03-23·CVSS 6.6
CVE-2026-33176 [MEDIUM] CWE-770 Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
A flaw was found in Active Support, a toolkit of support libraries for Ruby on Rails. A remote attacker can exploit this vulnerability by providing specially crafted strings co
Debian
CVE-2026-33176: rails - Active Support is a toolkit of support libraries and Ruby core extensions extrac...
vendor_debian·2026·CVSS 6.6
CVE-2026-33176 [MEDIUM] CVE-2026-33176: rails - Active Support is a toolkit of support libraries and Ruby core extensions extrac...
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33176 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-33176 [MEDIUM] CVE-2026-33176 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33176 :
Ruby vulnerability analysis and mitigation
1e10000
BigDecimal
Source : NVD
## 6.6
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.6
Affected Technologies
Ruby
Rails
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
activesupport
cinc-auditor
Sources
Chainguard Has Fix Added at: Mar 25, 2026
Debian 11, 14 Severity HIGH No Fix Added at: Mar 26, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Mar 26, 2026
Echo Severity HIGH No Fix Added at: Mar 26, 2026
RubyGems Severity MEDIUM Has Fix Added at: Mar 24, 2026
MinimOS Severity HIGH Has Fix Added at: Mar 24, 2026
Linux Sever
Bugzilla
CVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
bugzilla·2026-03-24·CVSS 6.6
CVE-2026-33176 [MEDIUM] CVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
CVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Discussion:
This issue has been addressed in the following products:
Red Hat Satellite 6.17 for RHEL 9
Via RHSA-2026:14873 https://access.redhat.com/errata/RH
https://github.com/rails/rails/commit/19dbab51ca086a657bb86458042bc44314916bcbhttps://github.com/rails/rails/commit/ebd6be18120d1136511eb516338e27af25ac0a1ahttps://github.com/rails/rails/commit/ee2c59e730e5b8faed502cd2c573109df093f856https://github.com/rails/rails/releases/tag/v7.2.3.1https://github.com/rails/rails/releases/tag/v8.0.4.1https://github.com/rails/rails/releases/tag/v8.1.2.1https://github.com/rails/rails/security/advisories/GHSA-2j26-frm8-cmj9
2026-03-24
Published