Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 44 rubygem-json 2.19.2 Format Injection Risk Notice 2026-3a7663d43d

fedora
Calendar Grey March 28, 2026
Dist Fedora Esm H88
A new Fedora update addresses a critical format injection issue in rubygem-json by upgrading to version 2.19.2.
New version 2.19.2 is released

Summary

This is a implementation of the JSON specification according

to RFC 4627 in Ruby.

You can think of it as a low fat alternative to XML,

if you want to store data to disk or transmit it over

a network rather than use a verbose markup language.

Update Information:

New version 2.19.2 is released. This fixes a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210

Change Log

* Thu Mar 19 2026 Mamoru TASAKA - 2.19.2-1 - 2.19.2 - Fixes CVE-2026-33210

References

Fedora Update Notification FEDORA-2026-3a7663d43d 2026-03-28 00:15:26.019819+00:00 Name : rubygem-json Product : Fedora 44 Version : 2.19.2 Release : 1.fc44 URL : https://github.com/ruby/json Summary : A JSON implementation in Ruby Description : This is a implementation of the JSON specification according to RFC 4627 in Ruby. You can think of it as a low fat alternative to XML, if you want to store data to disk or transmit it over a network rather than use a verbose markup language.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3a7663d43d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: rubygem-json
Product: Fedora 44
Version: 2.19.2
Release: 1.fc44
Summary: A JSON implementation in Ruby

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here