What the vulnerability does

01Description

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

Key dates

02Disclosure timeline

January 4, 2024 CVE published
May 14, 2026 Record updated