CVE-2026-97853
Received Received - Intake

Memory Allocation DoS in Decimal Elixir Library

Vulnerability report for CVE-2026-97853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: EEF

Description

Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service. Decimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new("1.5"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places. Any application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument. This issue affects decimal: from 0.1.0 before 3.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ericmj decimal 0.1.0
ericmj decimal 05bb73eb40ddef24eda782d905766f56a3660522

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory allocation issue in the ericmj decimal library's Decimal.round/3 function. It builds the full result for the requested decimal places before applying the default precision limit, causing memory usage to grow with the places argument instead of the actual result size. For example, calling Decimal.round(Decimal.new("1.5"), -50_000_000) allocates about 5.5 GB of memory, potentially exhausting system resources and crashing the BEAM VM.

Detection Guidance

Check if your system uses the vulnerable ericmj decimal library versions 0.1.0 to 3.1.1. Run commands like 'mix deps' in Elixir or 'rebar3 deps' in Erlang to list dependencies. Look for the decimal package version. If present and within the vulnerable range, the system is exposed.

Impact Analysis

This vulnerability can impact you by causing denial-of-service (DoS) conditions. Attackers could exploit it to exhaust system memory or CPU resources by passing extremely large values to the places argument in Decimal.round/2 or Decimal.round/3. This may crash applications or the entire BEAM VM, especially in memory-constrained environments like containers.

Mitigation Strategies
  • Upgrade the decimal library to version 3.1.2 or later to patch the vulnerability.
  • If upgrading is not immediately possible, implement input validation to bound the places argument passed to Decimal.round/2 or Decimal.round/3 functions.
  • Review applications using the decimal library to ensure user-supplied inputs to rounding functions are properly sanitized and bounded.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart