CVE-2026-33169: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33169 is a Regular Expression Denial of Service (ReDoS) vulnerability in the NumberToDelimitedConverter component of Ruby on Rails' Active Support library. The flaw causes quadratic time complexity when processing long digit strings due to the interaction between a lookahead-based regular expression and Ruby's gsub! method. It affects Active Support versions prior to 7.2.3.1, 8.0.x prior to 8.0.4.1, and 8.1.x prior to 8.1.2.1. Disclosed on March 23, 2026, it carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Feedly). The vulnerability was responsibly reported by HackerOne researcher scyoon (credited as ch4n3-yoon) (GitHub Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity). In the vulnerable code, NumberToDelimitedConverter#parts calls left.gsub!(delimiter_pattern) where delimiter_pattern is a lookahead-based regex; the repeated lookahead group causes the regex engine to exhibit quadratic backtracking behavior as the length of the digit string grows (GitHub Advisory). The fix replaces the regex-based approach with a linear string-slicing algorithm that splits the digit string into groups of three without using a regular expression when no custom delimiter pattern is specified (Rails Commit). Exploitation requires no authentication or special privileges — any network-accessible endpoint that passes user-controlled input to number_to_delimited is potentially vulnerable (Feedly).

Impact

Successful exploitation causes severe CPU exhaustion on the affected Rails application server, leading to service degradation or complete unavailability for legitimate users. There is no confidentiality or integrity impact — the vulnerability is limited to availability (DoS). Applications that expose number_to_delimited formatting to user-supplied numeric strings (e.g., via API endpoints or form inputs) are at greatest risk, and repeated requests with crafted long digit strings could sustain a denial-of-service condition (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term (Feedly). No threat actor attribution has been reported.

Exploitation steps

  1. Identify target endpoints: Locate a Rails application running an affected Active Support version (< 7.2.3.1, 8.0.x < 8.0.4.1, or 8.1.x < 8.1.2.1) that passes user-supplied numeric input to the number_to_delimited helper (e.g., via a public API or web form that formats numbers).
  2. Craft a malicious payload: Construct an extremely long digit string (e.g., thousands of digits with no decimal point) designed to trigger quadratic regex backtracking in NumberToDelimitedConverter.
  3. Submit the payload: Send repeated HTTP requests containing the crafted digit string to the vulnerable endpoint, causing the server's Ruby process to spend excessive CPU time evaluating the lookahead-based regex.
  4. Sustain the attack: Continue sending requests to maintain CPU saturation, resulting in application slowdown or complete unresponsiveness for other users (GitHub Advisory, Feedly).

Indicators of compromise

  • Network: Unusually high volume of HTTP requests to endpoints that accept numeric input for formatting; requests containing abnormally long digit strings in parameters.
  • Logs: Rails application logs showing repeated requests with very large numeric string parameters; elevated response times or timeouts on endpoints using number_to_delimited.
  • Process: Sustained high CPU utilization by the Ruby/Rails worker process without a corresponding increase in legitimate traffic; Ruby process appearing unresponsive or slow to handle new requests.

Mitigation and workarounds

Upgrade Active Support (and Rails) to the patched versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1 (Rails Release, GitHub Advisory). As a short-term workaround, implement input validation to enforce a maximum length on numeric strings before they are passed to number_to_delimited, and apply rate limiting on API endpoints that accept numeric inputs requiring formatting (Feedly). IBM has also released patches for affected downstream products including Aspera Faspex, Aspera Enterprise WebApps, Aspera Shares, CloudPak for AIOps, and License Metric Tool (IBM Aspera Faspex, IBM CloudPak AIOps).

Community reactions

The Rails team published a security advisory and released patched versions on March 23, 2026, alongside fixes for several other CVEs in the same release (Rails Release). IBM subsequently issued security bulletins for multiple affected products incorporating the upstream fix (IBM Aspera Faspex). Community reaction has been low-key given the Medium severity rating and absence of active exploitation; the vulnerability was noted in standard CVE tracking feeds and security blogs without significant alarm (dev.to CVE Report).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management