CVE-2026-33306 | bcrypt-ruby up to 3.1.21 on JRuby BCrypt.java integer overflow (GHSA-f27w-vcwj-c954 / Nessus ID 303306)
A vulnerability, which was classified as problematic, was found in bcrypt-ruby up to 3.1.21 on JRuby. The affected element is an unknown function of the file BCrypt.java. The manipulation results in integer overflow.
This vulnerability was named CVE-2026-33306. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.