CVE-2026-32686: Skip Unbounded Decimal Parsing

The decimal library explicitly delegated untrusted binary inputs to an unbound recursive descent parser (`parse_unsign`) and arithmetic functions without dynamically enforcing constraints on digit counts or maximum exponent sizes. This unconstrained logic enabled excessive memory allocations. Use `parse_with_limits` to enforce boundaries.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Elixir
greprules fetch cve-2026-32686-skip-unbounded-decimal-parsing --engine opengrep

Description

The decimal library explicitly delegated untrusted binary inputs to an unbound recursive descent parser (`parse_unsign`) and arithmetic functions without dynamically enforcing constraints on digit counts or maximum exponent sizes. This unconstrained logic enabled excessive memory allocations. Use `parse_with_limits` to enforce boundaries.