Security advisory: Decimal DoS vulnerability

:warning: Security advisory: Decimal DoS vulnerability

A vulnerability has been published for decimal where very large exponents can cause excessive memory allocation and crash the BEAM VM.

Affected versions: decimal < 3.0.0
Fixed in: decimal 3.0.0
CVE: CVE-2026-32686
GHSA: GHSA-rhv4-8758-jx7v

We recommend updating immediately.

decimal v3.0.0 enforces safer defaults. This is technically a breaking change, but for most use cases it should not require application changes. If needed, we recommend overriding the dependency explicitly:

{:decimal, "~> 3.0", override: true}
16 Likes

Just upgraded to 3.0.0 and ran a pretty slow financial test suite from scratch. No regressions! Great work, thank you.

1 Like

Better upgrade to 3.1, 3.0 has a bug that causes an infinite loop.

It caused my tests to hang.

2 Likes

Thank you for reporting it.

Does anyone know/understand why mix deps.audit doesn’t report it?

MixAudit relies on the GitHub Advisory DB. It is unfortunately often a few days out of date. In this case as well.

We’re however working on integrating this directly as warnings in deps.get and hex.audit. (Currently only checks for retirement status; You can already see the vulnerabilities on hex.pm package pages).

The data there relies on OSV.dev and therefore directly contains EEF CNA, GHSA and other reporters, see OSV - Open Source Vulnerabilities

3 Likes

Thanks for the explanation, now I get the reason for this post I guess :stuck_out_tongue: . I didn’t know it was absent from the GitHub Advisory DB, I assumed it was there already since it’s been assigned GHSA ID :grimacing:

Happy to know that you’re aware of it and there is work being done to improve the tools :crossed_fingers:

Well I actually mistyped. I’m on 3.1.0 indeed.

1 Like

If I run mix hex.audit today I get:

Run mix hex.audit
Advisories:
Found packages with security advisories
  decimal 3.1.1 - EEF-CVE-2026-32686 (MEDIUM)
    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v
    Unbounded exponent in decimal enables unauthenticated DoS
    https://osv.dev/vulnerability/EEF-CVE-2026-32686

I am on 3.1.1 of decimal.

But is 3.1.1 really affected by this? If yes - then is there a version with mitigation in the works? I can skip the advisory, but I wonder what’s a proper way to handling it.

@gmile We had an error in the record. It has a defaultStatus of affected and declared more affected ranges.

Before a new release of our tooling yesterday, that error did not surface since defaultStatus was not supported. Now that it is, it correctly deduced that all versions are affected.

I have corrected it so that the defaultStatus is unaffected.

2 Likes

Thank you for a quick fix, much appreciated!