{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-33210",
        "tracking": {
            "current_release_date": "2026-03-29T16:14:29.818270Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-33210",
            "initial_release_date": "2026-03-19T15:31:27.749007Z",
            "revision_history": [
                {
                    "date": "2026-03-19T15:31:27.749007Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:31:31.920199Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-20T23:25:33.705585Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T23:25:38.328274Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T23:39:24.615940Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T23:39:28.543459Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-21T12:45:13.779730Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products created (2)."
                },
                {
                    "date": "2026-03-21T12:45:18.127757Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-21T15:23:08.530738Z",
                    "number": "9",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-21T15:23:11.364275Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-21T18:44:38.534542Z",
                    "number": "11",
                    "summary": "Products connected (2).| Products removed (2)."
                },
                {
                    "date": "2026-03-21T18:44:40.127645Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-23T12:30:36.236578Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (29).| Product Identifiers created (7).| Product Remediations created (32).| Products created (3).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-23T12:30:45.834359Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-23T12:47:48.611444Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (12).| Product Identifiers created (12).| Products connected (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-23T12:47:56.743706Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:41:58.233740Z",
                    "number": "17",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-25T18:42:01.168120Z",
                    "number": "18",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-26T00:41:26.448683Z",
                    "number": "19",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-28T07:40:01.413541Z",
                    "number": "20",
                    "summary": "CVSS created.| Products created (3).| Product Identifiers created (3)."
                },
                {
                    "date": "2026-03-28T07:40:04.312838Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-29T03:16:18.618948Z",
                    "number": "22",
                    "summary": "References removed (2)."
                },
                {
                    "date": "2026-03-29T16:14:25.109036Z",
                    "number": "23",
                    "summary": "References created (2)."
                }
            ],
            "status": "interim",
            "version": "23"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2023",
                                "product": {
                                    "name": "vers:rpm/2023",
                                    "product_id": "CSAFPID-1492531",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_clients:2023"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "AMQ Clients"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/5",
                                "product": {
                                    "name": "vers:rpm/5",
                                    "product_id": "CSAFPID-1459353",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:logging:5"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1439310",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat 3scale API Management Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-5198605",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux AI (RHEL AI) 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5499196"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "backend"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5499197"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "backend-rhel7"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5499198"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "backend-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360337"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360339"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel7"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360342"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360344"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5011661"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "zync"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5011662"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "zync-rhel7"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2821639"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "zync-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2821640"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "zync-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat 3scale API Management Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3010673"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cluster-logging-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496167"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cluster-logging-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2485093"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "eventrouter-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2821638"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "fluentd-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914700"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "log-file-metric-exporter-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914698"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "logging-view-plugin-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3010674"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "vector-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5891525"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "json"
                            }
                        ],
                        "category": "product_family",
                        "name": "AMQ Clients"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5891527"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "json"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux AI (RHEL AI) 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109952"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pcs"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2042305"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3010731"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5891526"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby4.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2042307"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.14.0",
                                "product": {
                                    "name": "vers:unknown/2.14.0",
                                    "product_id": "CSAFPID-5891587",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.14.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.14.1",
                                "product": {
                                    "name": "vers:unknown/2.14.1",
                                    "product_id": "CSAFPID-5891588",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.14.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.15.0",
                                "product": {
                                    "name": "vers:unknown/2.15.0",
                                    "product_id": "CSAFPID-5891589",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.15.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.15.1",
                                "product": {
                                    "name": "vers:unknown/2.15.1",
                                    "product_id": "CSAFPID-5891590",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.15.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.15.2",
                                "product": {
                                    "name": "vers:unknown/2.15.2",
                                    "product_id": "CSAFPID-5891591",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.15.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.16.0",
                                "product": {
                                    "name": "vers:unknown/2.16.0",
                                    "product_id": "CSAFPID-5891584",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.16.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.17.0",
                                "product": {
                                    "name": "vers:unknown/2.17.0",
                                    "product_id": "CSAFPID-5891585",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.17.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.17.1",
                                "product": {
                                    "name": "vers:unknown/2.17.1",
                                    "product_id": "CSAFPID-5891586",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.17.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.18.0",
                                "product": {
                                    "name": "vers:unknown/2.18.0",
                                    "product_id": "CSAFPID-5891580",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.18.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.18.1",
                                "product": {
                                    "name": "vers:unknown/2.18.1",
                                    "product_id": "CSAFPID-5891581",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.18.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.19.0",
                                "product": {
                                    "name": "vers:unknown/2.19.0",
                                    "product_id": "CSAFPID-5891582",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.19.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.19.1",
                                "product": {
                                    "name": "vers:unknown/2.19.1",
                                    "product_id": "CSAFPID-5891583",
                                    "product_identification_helper": {
                                        "purl": "pkg:gem/json@2.19.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.14.0|<2.15.2.1",
                                "product": {
                                    "name": "vers:unknown/>=2.14.0|<2.15.2.1",
                                    "product_id": "CSAFPID-5878170"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.16.0|<2.17.1.2",
                                "product": {
                                    "name": "vers:unknown/>=2.16.0|<2.17.1.2",
                                    "product_id": "CSAFPID-5878171"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.18.0|<2.19.2",
                                "product": {
                                    "name": "vers:unknown/>=2.18.0|<2.19.2",
                                    "product_id": "CSAFPID-5878172"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "json"
                    }
                ],
                "category": "vendor",
                "name": "ruby"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.14.0|<2.15.2.1",
                                "product": {
                                    "name": "vers:unknown/>=2.14.0|<2.15.2.1",
                                    "product_id": "CSAFPID-5956288",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.16.0|<2.17.1.2",
                                "product": {
                                    "name": "vers:unknown/>=2.16.0|<2.17.1.2",
                                    "product_id": "CSAFPID-5956289",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.18.0|<2.19.2",
                                "product": {
                                    "name": "vers:unknown/>=2.18.0|<2.19.2",
                                    "product_id": "CSAFPID-5956290",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:ruby-lang:json:*:*:*:*:*:ruby:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "json"
                    }
                ],
                "category": "vendor",
                "name": "ruby-lang"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/*",
                                        "product": {
                                            "name": "vers:deb/*",
                                            "product_id": "CSAFPID-2474004"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby-json"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/*",
                                        "product": {
                                            "name": "vers:deb/*",
                                            "product_id": "CSAFPID-2474005"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ruby-json"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-33210",
            "cwe": {
                "id": "CWE-134",
                "name": "Use of Externally-Controlled Format String"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Impact\n\nA format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the `allow_duplicate_key: false` parsing option is used to parse user supplied documents. \n\nThis option isn't the default, if you didn't opt-in to use it, you are not impacted.\n\n### Patches\n\nPatched in `2.19.2`.\n\n### Workarounds\n\nThe issue can be avoided by not using the `allow_duplicate_key: false` parsing option.",
                    "title": "github - https://api.github.com/advisories/GHSA-3m6g-2423-7cp3"
                },
                {
                    "category": "description",
                    "text": "Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33210"
                },
                {
                    "category": "description",
                    "text": "Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33210.json"
                },
                {
                    "category": "description",
                    "text": "Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-33210"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Ruby JSON. This vulnerability, a format string injection, allows a remote attacker to cause a denial of service (DoS) or disclose sensitive information. The flaw occurs when processing specially crafted user-supplied documents with the allow_duplicate_key: false parsing option enabled.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-33210.json"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\nA format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the `allow_duplicate_key: false` parsing option is used to parse user supplied documents. \n\nThis option isn't the default, if you didn't opt-in to use it, you are not impacted.\n\n### Patches\n\nPatched in `2.19.2`.\n\n### Workarounds\n\nThe issue can be avoided by not using the `allow_duplicate_key: false` parsing option.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/RubyGems%2FGHSA-3m6g-2423-7cp3.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00016",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.2",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Red Hat, There is product_remediation data available from source Redhat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5878170",
                    "CSAFPID-5878171",
                    "CSAFPID-5878172",
                    "CSAFPID-1439310",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1459353",
                    "CSAFPID-1492531",
                    "CSAFPID-1496167",
                    "CSAFPID-2042305",
                    "CSAFPID-2042307",
                    "CSAFPID-2109952",
                    "CSAFPID-2485093",
                    "CSAFPID-2821638",
                    "CSAFPID-2821639",
                    "CSAFPID-2821640",
                    "CSAFPID-2858634",
                    "CSAFPID-2914698",
                    "CSAFPID-2914700",
                    "CSAFPID-3010673",
                    "CSAFPID-3010674",
                    "CSAFPID-3010731",
                    "CSAFPID-5011661",
                    "CSAFPID-5011662",
                    "CSAFPID-5198605",
                    "CSAFPID-5360337",
                    "CSAFPID-5360339",
                    "CSAFPID-5360342",
                    "CSAFPID-5360344",
                    "CSAFPID-5499196",
                    "CSAFPID-5499197",
                    "CSAFPID-5499198",
                    "CSAFPID-5891525",
                    "CSAFPID-5891526",
                    "CSAFPID-5891527",
                    "CSAFPID-5891580",
                    "CSAFPID-5891581",
                    "CSAFPID-5891582",
                    "CSAFPID-5891583",
                    "CSAFPID-5891584",
                    "CSAFPID-5891585",
                    "CSAFPID-5891586",
                    "CSAFPID-5891587",
                    "CSAFPID-5891588",
                    "CSAFPID-5891589",
                    "CSAFPID-5891590",
                    "CSAFPID-5891591",
                    "CSAFPID-5956288",
                    "CSAFPID-5956289",
                    "CSAFPID-5956290"
                ],
                "known_not_affected": [
                    "CSAFPID-2474004",
                    "CSAFPID-2474005"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-3m6g-2423-7cp3"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33210"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33210.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-33210"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-33210.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/RubyGems%2FGHSA-3m6g-2423-7cp3.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/ruby/json/security/advisories/GHSA-3m6g-2423-7cp3"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-3m6g-2423-7cp3"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-33210"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33210"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2026-33210.yml"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "To mitigate this vulnerability, avoid using the `allow_duplicate_key: false` parsing option when processing untrusted JSON input. If this option is required, ensure that all input is from trusted sources or is thoroughly sanitized before parsing.",
                    "product_ids": [
                        "CSAFPID-1439310",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1459353",
                        "CSAFPID-1492531",
                        "CSAFPID-1496167",
                        "CSAFPID-2042305",
                        "CSAFPID-2042307",
                        "CSAFPID-2109952",
                        "CSAFPID-2485093",
                        "CSAFPID-2821638",
                        "CSAFPID-2821639",
                        "CSAFPID-2821640",
                        "CSAFPID-2858634",
                        "CSAFPID-2914698",
                        "CSAFPID-2914700",
                        "CSAFPID-3010673",
                        "CSAFPID-3010674",
                        "CSAFPID-3010731",
                        "CSAFPID-5011661",
                        "CSAFPID-5011662",
                        "CSAFPID-5198605",
                        "CSAFPID-5360337",
                        "CSAFPID-5360339",
                        "CSAFPID-5360342",
                        "CSAFPID-5360344",
                        "CSAFPID-5499196",
                        "CSAFPID-5499197",
                        "CSAFPID-5499198",
                        "CSAFPID-5891525",
                        "CSAFPID-5891526",
                        "CSAFPID-5891527"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1439310",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1459353",
                        "CSAFPID-1492531",
                        "CSAFPID-1496167",
                        "CSAFPID-2042305",
                        "CSAFPID-2042307",
                        "CSAFPID-2109952",
                        "CSAFPID-2485093",
                        "CSAFPID-2821638",
                        "CSAFPID-2821639",
                        "CSAFPID-2821640",
                        "CSAFPID-2858634",
                        "CSAFPID-2914698",
                        "CSAFPID-2914700",
                        "CSAFPID-3010673",
                        "CSAFPID-3010674",
                        "CSAFPID-3010731",
                        "CSAFPID-5011661",
                        "CSAFPID-5011662",
                        "CSAFPID-5198605",
                        "CSAFPID-5360337",
                        "CSAFPID-5360339",
                        "CSAFPID-5360342",
                        "CSAFPID-5360344",
                        "CSAFPID-5499196",
                        "CSAFPID-5499197",
                        "CSAFPID-5499198",
                        "CSAFPID-5878170",
                        "CSAFPID-5878171",
                        "CSAFPID-5878172",
                        "CSAFPID-5891525",
                        "CSAFPID-5891526",
                        "CSAFPID-5891527",
                        "CSAFPID-5891580",
                        "CSAFPID-5891581",
                        "CSAFPID-5891582",
                        "CSAFPID-5891583",
                        "CSAFPID-5891584",
                        "CSAFPID-5891585",
                        "CSAFPID-5891586",
                        "CSAFPID-5891587",
                        "CSAFPID-5891588",
                        "CSAFPID-5891589",
                        "CSAFPID-5891590",
                        "CSAFPID-5891591",
                        "CSAFPID-5956288",
                        "CSAFPID-5956289",
                        "CSAFPID-5956290"
                    ]
                }
            ],
            "title": "CVE-2026-33210"
        }
    ]
}