VYPR
High severity7.5OSV Advisory· Published Jan 4, 2024· Updated Jul 14, 2026

CVE-2024-0241

CVE-2024-0241

Description

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
encoded_id-railsRubyGems
< 1.0.0.beta21.0.0.beta2

Affected products

5
  • Range: 1.0.0.beta1, v0.0.1, v0.3.0, …
  • cpe:2.3:a:diaconou:encodedid\:\:rails:*:*:*:*:*:ruby:*:*+ 2 more
    • cpe:2.3:a:diaconou:encodedid\:\:rails:*:*:*:*:*:ruby:*:*range: <1.0.0
    • cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:-:*:*:*:ruby:*:*
    • cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:beta1:*:*:*:ruby:*:*
  • ghsa-coords
    Range: < 1.0.0.beta2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.