CVE-2024-0241: Diaconou Encodedid::rails
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.
Affected products
- Diaconou Encodedid::rails: before 1.0.0 (fixed in 1.0.0); version 1.0.0 only
Published 2024-01-04. Last modified 2026-07-14.