CVE-2026-33169: Ruby Rails Number To Delimited Redos
Algorithmic complexity vulnerability (ReDoS) due to lookahead-heavy regex repeatedly evaluated via `gsub!`. The `NumberToDelimitedConverter` uses `gsub!` with a lookahead-based regular expression (`delimiter_pattern`) across the entire string without constraints, causing O(N^2) complexity on long digit strings. Ensure string manipulations on large untrusted
greprules fetch cve-2026-33169-ruby-rails-number-to-delimited-redos --engine opengrepDescription
Algorithmic complexity vulnerability (ReDoS) due to lookahead-heavy regex repeatedly evaluated via `gsub!`. The `NumberToDelimitedConverter` uses `gsub!` with a lookahead-based regular expression (`delimiter_pattern`) across the entire string without constraints, causing O(N^2) complexity on long digit strings. Ensure string manipulations on large untrusted
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.