CVE-2024-0241: Diaconou Encodedid::rails

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

Affected products

  • Diaconou Encodedid::rails: before 1.0.0 (fixed in 1.0.0); version 1.0.0 only

Published 2024-01-04. Last modified 2026-07-14.