CVE-2026-33210
Impact
A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the allowduplicatekey: false parsing option is used to parse user supplied documents.
This option isn't the default, if you didn't opt-in to use it, you are not impacted.
Patches
Patched in 2.19.2.
Workarounds
The issue can be avoided by not using the allowduplicatekey: false parsing option.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3, https://nvd.nist.gov/vuln/detail/CVE-2026-33210, https://github.com/ruby/json, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2026-33210.yml
