CVE-2026-33210 | Ruby json up to 2.19.1 allow_duplicate_key format string (GHSA-3m6g-2423-7cp3 / Nessus ID 303258)
A vulnerability was found in Ruby json up to 2.19.1. It has been rated as critical. This affects the function allow_duplicate_key. Performing a manipulation results in format string.
This vulnerability was named CVE-2026-33210. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.