CVE-2026-33210: Ruby JSON has a format string injection vulnerability
A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents.
This option isn’t the default, if you didn’t opt-in to use it, you are not impacted.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33210 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →