
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33169 is a Regular Expression Denial of Service (ReDoS) vulnerability in the NumberToDelimitedConverter component of Ruby on Rails' Active Support library. The flaw causes quadratic time complexity when processing long digit strings due to the interaction between a lookahead-based regular expression and Ruby's gsub! method. It affects Active Support versions prior to 7.2.3.1, 8.0.x prior to 8.0.4.1, and 8.1.x prior to 8.1.2.1. Disclosed on March 23, 2026, it carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Feedly). The vulnerability was responsibly reported by HackerOne researcher scyoon (credited as ch4n3-yoon) (GitHub Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity). In the vulnerable code, NumberToDelimitedConverter#parts calls left.gsub!(delimiter_pattern) where delimiter_pattern is a lookahead-based regex; the repeated lookahead group causes the regex engine to exhibit quadratic backtracking behavior as the length of the digit string grows (GitHub Advisory). The fix replaces the regex-based approach with a linear string-slicing algorithm that splits the digit string into groups of three without using a regular expression when no custom delimiter pattern is specified (Rails Commit). Exploitation requires no authentication or special privileges — any network-accessible endpoint that passes user-controlled input to number_to_delimited is potentially vulnerable (Feedly).
Successful exploitation causes severe CPU exhaustion on the affected Rails application server, leading to service degradation or complete unavailability for legitimate users. There is no confidentiality or integrity impact — the vulnerability is limited to availability (DoS). Applications that expose number_to_delimited formatting to user-supplied numeric strings (e.g., via API endpoints or form inputs) are at greatest risk, and repeated requests with crafted long digit strings could sustain a denial-of-service condition (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term (Feedly). No threat actor attribution has been reported.
number_to_delimited helper (e.g., via a public API or web form that formats numbers).NumberToDelimitedConverter.number_to_delimited.Upgrade Active Support (and Rails) to the patched versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1 (Rails Release, GitHub Advisory). As a short-term workaround, implement input validation to enforce a maximum length on numeric strings before they are passed to number_to_delimited, and apply rate limiting on API endpoints that accept numeric inputs requiring formatting (Feedly). IBM has also released patches for affected downstream products including Aspera Faspex, Aspera Enterprise WebApps, Aspera Shares, CloudPak for AIOps, and License Metric Tool (IBM Aspera Faspex, IBM CloudPak AIOps).
The Rails team published a security advisory and released patched versions on March 23, 2026, alongside fixes for several other CVEs in the same release (Rails Release). IBM subsequently issued security bulletins for multiple affected products incorporating the upstream fix (IBM Aspera Faspex). Community reaction has been low-key given the Medium severity rating and absence of active exploitation; the vulnerability was noted in standard CVE tracking feeds and security blogs without significant alarm (dev.to CVE Report).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."