Memory Allocation Vulnerability in ericmj Decimal Library
CVE-2026-97853
6.9MEDIUM
What is CVE-2026-97853?
A memory allocation vulnerability exists in the ericmj Decimal library, where the Decimal.round/3 function allows an attacker to specify an excessively large number of decimal places. This leads to dramatic memory consumption, causing Denial of Service (DoS) as it can allocate massive amounts of memory, potentially exhausting system resources. Applications that do not impose limits on user-supplied inputs for the places argument are particularly at risk. The library’s behavior can lead to substantial performance degradation or complete failure of the BEAM VM, making it imperative for developers to implement input validations.
Affected Version(s)
decimal 0.1.0 < 3.1.2
decimal 05bb73eb40ddef24eda782d905766f56a3660522
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Eric Meadows-Jönsson
Eric Meadows-Jönsson
