encoded_id-rails
ActiveRecord concern to use EncodedID to turn IDs into reversible and human friendly obfuscated strings.
Activity
- Latest release
- 7mo ago
- Total releases
- 17
- Cadence
- ~15 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Nov 17, 2022
| Version | Released | |
|---|---|---|
1.1.0
minor
| ||
1.0.0
major
| ||
1.0.0.rc7
pre
| ||
1.0.0.rc6
pre
| ||
1.0.0.rc1
pre
| ||
1.0.0.beta3
pre
| ||
1.0.0.beta2
pre
| ||
1.0.0.beta1
pre
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2024-0241
GHSA-3px7-jm2p-6h2c
Oct 24, 2023
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe length of URIs and the various parts (eg path segments, query parameters) is usually limited by the webserver processing the incoming request. In the case of Puma the defaults are :
See https://github.com/puma/puma/blob/master/docs/compile_options.md If too long Puma raises:
However due to the performance of For example:
This causes the application to spend a huge amount of time decoding the ID and the allocation of > 200MB of objects. PatchesUpgrade to This introduces a new option to limit the length of IDs that can be decoded. A future release will also improve the performance and hugely reduce allocations in the underlying hashids implementation. ReferencesAre there any links users can visit to find out more? Affected versions
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
1.0.0.beta1
Fixed in
1.0.0.beta2
References
Updated Jul 08, 2026 · Source: OSV.dev |