๐Ÿ” CVE Alert

CVE-2026-33169

UNKNOWN 0.0

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
4th

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, the interaction between the repeated lookahead group and `gsub!` can produce quadratic time complexity on long digit strings. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CWE CWE-400 CWE-1333
Vendor rails
Product activesupport
Published Mar 23, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for rails activesupport

Be the first to know when new unknown vulnerabilities affecting rails activesupport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

rails / activesupport
>= 8.1.0.beta1, < 8.1.2.1 >= 8.0.0.beta1, < 8.0.4.1 < 7.2.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rails/rails/security/advisories/GHSA-cg4j-q9v8-6v38 github.com: https://github.com/rails/rails/commit/29154f1097da13d48fdb3200760b3e3da66dcb11 github.com: https://github.com/rails/rails/commit/b54a4b373c6f042cab6ee2033246b1c9ecc38974 github.com: https://github.com/rails/rails/commit/ec1a0e215efd27a3b3911aae6df978a80f456a49 github.com: https://github.com/rails/rails/releases/tag/v7.2.3.1 github.com: https://github.com/rails/rails/releases/tag/v8.0.4.1 github.com: https://github.com/rails/rails/releases/tag/v8.1.2.1