Report: CVE-2026-32686 - Unbounded exponent in decimal enables unauthenticated DoS

Report: CVE-2026-32686 - Unbounded exponent in decimal enables unauthenticated DoS

CVE ID :CVE-2026-32686 Published : May 7, 2026, 2:04 p.m. | 1 hour ago Description :Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decimal.new(

CVE Details

Published
May 7, 2026
Impact: Denial of Service