{"api_version":"1","generated_at":"2026-10-10T21:41:08+00:00","cve":"CVE-2026-97853","urls":{"html":"https://cve.report/CVE-2026-97853","api":"https://cve.report/api/cve/CVE-2026-97853.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97853","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97853"},"summary":{"title":"Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoS","description":"Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.\n\nDecimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new(\"1.5\"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places.\n\nAny application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument.\n\nThis issue affects decimal: from 0.1.0 before 3.1.2.","state":"PUBLISHED","assigner":"EEF","published_at":"2026-10-10 20:16:47","updated_at":"2026-10-10 20:16:47"},"problem_types":["CWE-789","CWE-789 CWE-789 Memory Allocation with Excessive Size Value"],"metrics":[{"version":"4.0","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/ericmj/decimal/commit/3c90af4c3c2dfa4bb4c138760a326dd0eb91822b","name":"https://github.com/ericmj/decimal/commit/3c90af4c3c2dfa4bb4c138760a326dd0eb91822b","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-97853","name":"https://osv.dev/vulnerability/EEF-CVE-2026-97853","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cna.erlef.org/cves/CVE-2026-97853.html","name":"https://cna.erlef.org/cves/CVE-2026-97853.html","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ericmj/decimal/commit/05bb73eb40ddef24eda782d905766f56a3660522","name":"https://github.com/ericmj/decimal/commit/05bb73eb40ddef24eda782d905766f56a3660522","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ericmj/decimal/commit/338f42c8cf6a9749ab70c5af04734c6050ca3dc6","name":"https://github.com/ericmj/decimal/commit/338f42c8cf6a9749ab70c5af04734c6050ca3dc6","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ericmj/decimal/security/advisories/GHSA-6c27-994x-c52f","name":"https://github.com/ericmj/decimal/security/advisories/GHSA-6c27-994x-c52f","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97853","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97853","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ericmj","product":"decimal","version":"affected 0.1.0 3.1.2 semver","platforms":[]},{"source":"CNA","vendor":"ericmj","product":"decimal","version":"affected 05bb73eb40ddef24eda782d905766f56a3660522 * git","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Bound places before calling Decimal.round/2,3, for example to -34..34 or to the scales the application supports.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Peter Ullrich","lang":"en"},{"source":"CNA","value":"Eric Meadows-Jönsson","lang":"en"},{"source":"CNA","value":"Eric Meadows-Jönsson","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:ericmj:decimal:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Decimal'"],"packageName":"decimal","packageURL":"pkg:hex/decimal","product":"decimal","programFiles":["lib/decimal.ex"],"programRoutines":[{"name":"'Elixir.Decimal':round/2"},{"name":"'Elixir.Decimal':round/3"}],"repo":"https://github.com/ericmj/decimal","vendor":"ericmj","versions":[{"lessThan":"3.1.2","status":"affected","version":"0.1.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:ericmj:decimal:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Decimal'"],"packageName":"ericmj/decimal","packageURL":"pkg:github/ericmj/decimal","product":"decimal","programFiles":["lib/decimal.ex"],"programRoutines":[{"name":"'Elixir.Decimal':round/2"},{"name":"'Elixir.Decimal':round/3"}],"repo":"https://github.com/ericmj/decimal","vendor":"ericmj","versions":[{"changes":[{"at":"338f42c8cf6a9749ab70c5af04734c6050ca3dc6","status":"unaffected"},{"at":"3c90af4c3c2dfa4bb4c138760a326dd0eb91822b","status":"unaffected"}],"lessThan":"*","status":"affected","version":"05bb73eb40ddef24eda782d905766f56a3660522","versionType":"git"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:ericmj:decimal:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.2","versionStartIncluding":"0.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"Peter Ullrich"},{"lang":"en","type":"remediation developer","value":"Eric Meadows-Jönsson"},{"lang":"en","type":"coordinator","value":"Eric Meadows-Jönsson"}],"dateAssigned":"2026-10-09T16:40:13.000Z","datePublic":"2026-10-10T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.</p>\n<p><code>Decimal.round/3</code> builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the <code>places</code> argument instead of with the size of the result. For positive <code>places</code> it appends <code>places</code> zero digits to the coefficient as a charlist before converting it to an integer, and for negative <code>places</code> it builds a charlist of <code>-places</code> zero digits. A single call such as <code>Decimal.round(Decimal.new(\"1.5\"), -50_000_000)</code> allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to <code>places</code>.</p>\n<p>Any application that passes a user-supplied number of decimal places or scale to <code>Decimal.round/2</code> or <code>Decimal.round/3</code> without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the <code>places</code> argument.</p>\n<p>This issue affects decimal: from 0.1.0 before 3.1.2.</p>"},{"base64":false,"type":"text/markdown","value":"Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.\n\n`Decimal.round/3` builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the `places` argument instead of with the size of the result. For positive `places` it appends `places` zero digits to the coefficient as a charlist before converting it to an integer, and for negative `places` it builds a charlist of `-places` zero digits. A single call such as `Decimal.round(Decimal.new(\"1.5\"), -50_000_000)` allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to `places`.\n\nAny application that passes a user-supplied number of decimal places or scale to `Decimal.round/2` or `Decimal.round/3` without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the `places` argument.\n\nThis issue affects decimal: from 0.1.0 before 3.1.2."}],"value":"Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.\n\nDecimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new(\"1.5\"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places.\n\nAny application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument.\n\nThis issue affects decimal: from 0.1.0 before 3.1.2."}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An attacker who controls the number of decimal places an application rounds to makes one <code>Decimal.round/2,3</code> call allocate memory in proportion to that number. A value of 50 million needs about 5.5 GB, enough to get the BEAM VM killed on hosts with less memory and take down every request it serves.</p>"},{"base64":false,"type":"text/markdown","value":"An attacker who controls the number of decimal places an application rounds to makes one `Decimal.round/2,3` call allocate memory in proportion to that number. A value of 50 million needs about 5.5 GB, enough to get the BEAM VM killed on hosts with less memory and take down every request it serves."}],"value":"An attacker who controls the number of decimal places an application rounds to makes one Decimal.round/2,3 call allocate memory in proportion to that number. A value of 50 million needs about 5.5 GB, enough to get the BEAM VM killed on hosts with less memory and take down every request it serves."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-789","description":"CWE-789 Memory Allocation with Excessive Size Value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-10T19:43:45.217Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GHSA-6c27-994x-c52f","tags":["vendor-advisory"],"url":"https://github.com/ericmj/decimal/security/advisories/GHSA-6c27-994x-c52f"},{"name":"EEF CNA record for CVE-2026-97853","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-97853.html"},{"name":"OSV record EEF-CVE-2026-97853","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-97853"},{"name":"Introducing commit 05bb73e in ericmj/decimal","tags":["related"],"url":"https://github.com/ericmj/decimal/commit/05bb73eb40ddef24eda782d905766f56a3660522"},{"name":"Fix commit 338f42c in ericmj/decimal","tags":["patch"],"url":"https://github.com/ericmj/decimal/commit/338f42c8cf6a9749ab70c5af04734c6050ca3dc6"},{"name":"Fix commit 3c90af4 in ericmj/decimal","tags":["patch"],"url":"https://github.com/ericmj/decimal/commit/3c90af4c3c2dfa4bb4c138760a326dd0eb91822b"}],"source":{"discovery":"EXTERNAL"},"title":"Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoS","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Bound <code>places</code> before calling <code>Decimal.round/2,3</code>, for example to <code>-34..34</code> or to the scales the application supports.</p>"},{"base64":false,"type":"text/markdown","value":"Bound `places` before calling `Decimal.round/2,3`, for example to `-34..34` or to the scales the application supports."}],"value":"Bound places before calling Decimal.round/2,3, for example to -34..34 or to the scales the application supports."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre><code class=\"language-elixir\">Mix.install([{:decimal, \"3.1.1\"}])\n\n# Allocates about 5.5 GB.\nDecimal.round(Decimal.new(\"1.5\"), -50_000_000)\n\n# Builds a 50 million element list, then raises SystemLimitError.\nDecimal.round(Decimal.new(\"1.5\"), 50_000_000)\n</code></pre>"},{"base64":false,"type":"text/markdown","value":"```elixir\nMix.install([{:decimal, \"3.1.1\"}])\n\n# Allocates about 5.5 GB.\nDecimal.round(Decimal.new(\"1.5\"), -50_000_000)\n\n# Builds a 50 million element list, then raises SystemLimitError.\nDecimal.round(Decimal.new(\"1.5\"), 50_000_000)\n```"}],"value":"Mix.install([{:decimal, \"3.1.1\"}])\n\n# Allocates about 5.5 GB.\nDecimal.round(Decimal.new(\"1.5\"), -50_000_000)\n\n# Builds a 50 million element list, then raises SystemLimitError.\nDecimal.round(Decimal.new(\"1.5\"), 50_000_000)"}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><code>Decimal.round/3</code> sets the target exponent to <code>-places</code> and <code>do_round/5</code> materializes the coefficient at that exponent; <code>context/2</code> only applies the precision afterwards.</p>\n<ul>\n<li>Positive <code>places</code> (introduced in 1.3.0 by commit 7a83d27): <code>digits ++ Enum.map(1..(exp - target_exp), fn _ -&gt; ?0 end)</code> followed by <code>:erlang.list_to_integer/1</code> (<code>lib/decimal.ex:2409</code> in 3.1.1). The list is built before <code>list_to_integer/1</code> raises <code>SystemLimitError</code> for results over about 1.26 million digits, the BEAM integer size limit.</li>\n<li>Negative <code>places</code> (since 1.4.0): <code>:lists.duplicate(target_exp - exp, ?0) ++ digits</code> (<code>lib/decimal.ex:2385-2386</code> in 3.1.1).</li>\n<li>Releases from 0.1.0 before 1.1.0: <code>do_round</code> (and in 1.0.1 <code>split_coef</code>) recurses once per decimal place for negative <code>places</code>; 1.0.1 also multiplies a power of ten by 10 on every iteration. Established by reading the code; these releases do not compile on current Elixir.</li>\n</ul>\n<p>Measured on OTP 29 with 3.1.1, one call per fresh VM:</p>\n<table>\n<thead>\n<tr>\n<th>Call</th>\n<th>Time</th>\n<th>Peak VM memory</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>Decimal.round(Decimal.new(\"1.5\"), -10_000_000)</code></td>\n<td>0.25 s</td>\n<td>0.8 GB</td>\n</tr>\n<tr>\n<td><code>Decimal.round(Decimal.new(\"1.5\"), -50_000_000)</code></td>\n<td>1.2 s</td>\n<td>5.5 GB</td>\n</tr>\n<tr>\n<td><code>Decimal.round(Decimal.new(\"1.5\"), 50_000_000)</code></td>\n<td>2.1 s, then <code>SystemLimitError</code></td>\n<td>2.4 GB</td>\n</tr>\n</tbody>\n</table>\n<p>In an <code>elixir:1.20.4</code> container started with <code>--memory=2g</code>, either of the last two calls got the VM killed (exit status 137). Over HTTP (Plug and Bandit) a 34-byte JSON body carrying <code>places: -50_000_000</code> returned after 1.25 s with server memory at 4.3 GB.</p>"},{"base64":false,"type":"text/markdown","value":"`Decimal.round/3` sets the target exponent to `-places` and `do_round/5` materializes the coefficient at that exponent; `context/2` only applies the precision afterwards.\n\n- Positive `places` (introduced in 1.3.0 by commit 7a83d27): `digits ++ Enum.map(1..(exp - target_exp), fn _ -> ?0 end)` followed by `:erlang.list_to_integer/1` (`lib/decimal.ex:2409` in 3.1.1). The list is built before `list_to_integer/1` raises `SystemLimitError` for results over about 1.26 million digits, the BEAM integer size limit.\n- Negative `places` (since 1.4.0): `:lists.duplicate(target_exp - exp, ?0) ++ digits` (`lib/decimal.ex:2385-2386` in 3.1.1).\n- Releases from 0.1.0 before 1.1.0: `do_round` (and in 1.0.1 `split_coef`) recurses once per decimal place for negative `places`; 1.0.1 also multiplies a power of ten by 10 on every iteration. Established by reading the code; these releases do not compile on current Elixir.\n\nMeasured on OTP 29 with 3.1.1, one call per fresh VM:\n\n| Call | Time | Peak VM memory |\n|---|---|---|\n| `Decimal.round(Decimal.new(\"1.5\"), -10_000_000)` | 0.25 s | 0.8 GB |\n| `Decimal.round(Decimal.new(\"1.5\"), -50_000_000)` | 1.2 s | 5.5 GB |\n| `Decimal.round(Decimal.new(\"1.5\"), 50_000_000)` | 2.1 s, then `SystemLimitError` | 2.4 GB |\n\nIn an `elixir:1.20.4` container started with `--memory=2g`, either of the last two calls got the VM killed (exit status 137). Over HTTP (Plug and Bandit) a 34-byte JSON body carrying `places: -50_000_000` returned after 1.25 s with server memory at 4.3 GB."}],"value":"Decimal.round/3 sets the target exponent to -places and do_round/5 materializes the coefficient at that exponent; context/2 only applies the precision afterwards.\n\n* Positive places (introduced in 1.3.0 by commit 7a83d27): digits ++ Enum.map(1..(exp - target_exp), fn _ -> ?0 end) followed by :erlang.list_to_integer/1 (lib/decimal.ex:2409 in 3.1.1). The list is built before list_to_integer/1 raises SystemLimitError for results over about 1.26 million digits, the BEAM integer size limit.\n* Negative places (since 1.4.0): :lists.duplicate(target_exp - exp, ?0) ++ digits (lib/decimal.ex:2385-2386 in 3.1.1).\n* Releases from 0.1.0 before 1.1.0: do_round (and in 1.0.1 split_coef) recurses once per decimal place for negative places; 1.0.1 also multiplies a power of ten by 10 on every iteration. Established by reading the code; these releases do not compile on current Elixir.\n\nMeasured on OTP 29 with 3.1.1, one call per fresh VM:\n\nCallTimePeak VM memoryDecimal.round(Decimal.new(\"1.5\"), -10_000_000)0.25 s0.8 GBDecimal.round(Decimal.new(\"1.5\"), -50_000_000)1.2 s5.5 GBDecimal.round(Decimal.new(\"1.5\"), 50_000_000)2.1 s, then SystemLimitError2.4 GB\n\nIn an elixir:1.20.4 container started with --memory=2g, either of the last two calls got the VM killed (exit status 137). Over HTTP (Plug and Bandit) a 34-byte JSON body carrying places: -50_000_000 returned after 1.25 s with server memory at 4.3 GB."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-97853","datePublished":"2026-10-10T19:43:45.217Z","dateReserved":"2026-10-09T00:30:01.645Z","dateUpdated":"2026-10-10T19:43:45.217Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-10 20:16:47","lastModifiedDate":"2026-10-10 20:16:47","problem_types":["CWE-789","CWE-789 CWE-789 Memory Allocation with Excessive Size Value"],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97853","Ordinal":"1","Title":"Unbounded allocation in decimal Decimal.round/3 driven by the pl","CVE":"CVE-2026-97853","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97853","Ordinal":"1","NoteData":"Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.\n\nDecimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new(\"1.5\"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places.\n\nAny application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument.\n\nThis issue affects decimal: from 0.1.0 before 3.1.2.","Type":"Description","Title":"Unbounded allocation in decimal Decimal.round/3 driven by the pl"}]}}}