Get real-time updates on Telegram
Verified
CVE-2026-97853: decimal 0.1.0 to before 3.1.2
Affected technology
decimal · 0.1.0 to before 3.1.2
ericmj
decimal · 05bb73eb40ddef24eda782d905766f56a3660522 to before *; status changes: 338f42c8cf6a9749ab70c5af04734c6050ca3dc6 — unaffected, 3c90af4c3c2dfa4bb4c138760a326dd0eb91822b — unaffected
ericmj
Component: 'Elixir.Decimal'
Function: 'Elixir.Decimal':round/2, 'Elixir.Decimal':round/3
File: lib/decimal.ex
Attack conditions (Source advisory, CVSS 4.0): Local · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could disrupt service. Source advisory’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-789
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-10 20:34:26.585255+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-97853.html