CVE-2024-0241

CVE-2024-0241: encoded_id-rails Denial of Service Vulnerability

Weakness CWE-400
Published January 4, 2024
Last update May 14, 2026

CVSS base score

What the vulnerability does

Description

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

Key dates

Disclosure timeline

January 4, 2024 CVE published
May 14, 2026 Record updated