Memory Allocation Vulnerability in ericmj Decimal Library
CVE-2026-97853

6.9MEDIUM

Key Information:

Vendor

Ericmj

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-97853?

A memory allocation vulnerability exists in the ericmj Decimal library, where the Decimal.round/3 function allows an attacker to specify an excessively large number of decimal places. This leads to dramatic memory consumption, causing Denial of Service (DoS) as it can allocate massive amounts of memory, potentially exhausting system resources. Applications that do not impose limits on user-supplied inputs for the places argument are particularly at risk. The library’s behavior can lead to substantial performance degradation or complete failure of the BEAM VM, making it imperative for developers to implement input validations.

Affected Version(s)

decimal 0.1.0 < 3.1.2

decimal 05bb73eb40ddef24eda782d905766f56a3660522

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Eric Meadows-Jönsson
Eric Meadows-Jönsson
.