CVE-2026-33306 is an integer overflow vulnerability in the JRuby implementation of bcrypt-ruby (prior to version 3.1.22) when the hashing cost is set to 31. This flaw causes the password strengthening loop to execute zero iterations, drastically weakening the cryptographic protection of hashed passwords. Rated High severity (CVSS 7.5), this vulnerability can be exploited remotely with low complexity, leading to a high impact on confidentiality by making hashed passwords trivial to crack. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability, and its EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.22CPE matchmatch criteria | cpe:2.3:a:bcrypt-ruby_project:bcrypt-ruby:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.