unpoly-rails
Rails bindings for Unpoly, the unobtrusive JavaScript framework
Activity
- Latest release
- 4mo ago
- Total releases
- 149
- Cadence
- ~15 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Feb 26, 2016
| Version | Released | |
|---|---|---|
3.14.3
patch
| ||
3.14.2
patch
| ||
3.14.1
patch
| ||
3.14.0
minor
| ||
3.12.0
minor
| ||
3.11.0
minor
| ||
3.11.0.rc12
pre
| ||
3.11.0.rc1
pre
| ||
3.10.2
patch
| ||
3.10.0
minor
| ||
3.10.0.rc1
pre
| ||
3.9.5
patch
| ||
3.9.3.1
patch
| ||
3.9.3
patch
| ||
3.9.2.1
patch
| ||
3.9.2
patch
| ||
3.9.1
patch
| ||
3.9.0
minor
| ||
3.8.0.1
patch
| ||
3.8.0
minor
| ||
3.8.0.rc1
pre
| ||
3.7.3.2
patch
| ||
3.7.3.1
patch
| ||
3.7.3
patch
| ||
3.7.2
patch
| ||
3.7.1
patch
| ||
3.7.0.1
patch
| ||
3.7.0
minor
| ||
3.6.1.1
patch
| ||
3.6.1
patch
| ||
3.6.0
minor
| ||
3.5.2
patch
| ||
3.5.1
patch
| ||
3.5.0
minor
| ||
3.3.0.1
patch
| ||
3.3.0
minor
| ||
3.2.2.1
patch
| ||
3.2.2
patch
| ||
3.2.1
patch
| ||
3.2.0
minor
| ||
3.1.1
patch
| ||
3.1.0
minor
| ||
3.0.0
major
| ||
3.0.0.rc4
pre
| ||
3.0.0.rc3
pre
| ||
2.7.2.2
patch
| ||
2.7.2.1
patch
1 CVE
CVE-2023-28846
GHSA-m875-3xf6-mf78
Mar 30, 2023
unpoly-rails Denial of Service vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
There is a possible Denial of Service (DoS) vulnerability in the unpoly-rails gem that implements the Unpoly server protocol for Rails applications. ImpactThis issues affects Rails applications that operate as an upstream of a load balancer's that uses passive health checks. The unpoly-rails gem echoes the request URL as an If the response header is too large to be parsed by a load balancer downstream of the Rails application, it may cause the load balancer to remove the upstream from a load balancing group. This causes that application instance to become unavailable until a configured timeout is reached or until an active healthcheck succeeds. PatchesThe fixed release 2.7.2.2+ is available via RubyGems and GitHub. WorkaroundsIf you cannot upgrade to a fixed release, several workarounds are available:
Affected versions
0.20.0
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.25.0
0.25.1
0.25.2
0.26.0
0.26.1
+ 89 more Show less
0.26.2
0.27.0
0.27.1
0.27.2
0.27.3
0.28.0
0.28.1
0.29.0
0.30.0
0.30.1
0.31.0
0.31.1
0.31.2
0.32.0
0.33.0
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.36.0
0.36.1
0.36.2
0.37.0
0.50.0
0.50.1
0.50.2
0.51.0
0.51.1
0.52.0
0.53.0
0.53.1
0.53.2
0.53.3
0.53.4
0.54.0
0.54.1
0.55.0
0.55.1
0.56.0
0.56.1
0.56.2
0.56.3
0.56.4
0.56.5
0.56.6
0.56.7
0.57.0
0.60.0
0.60.1
0.60.2
0.60.3
0.61.0
0.61.1
0.62.0
0.62.1
1.0.0
1.0.1
1.0.3
2.0.0
2.0.0.pre.rc10
2.0.0.pre.rc11
2.0.0.pre.rc2
2.0.0.pre.rc3
2.0.0.pre.rc4
2.0.0.pre.rc5
2.0.0.pre.rc6
2.0.0.pre.rc7
2.0.0.pre.rc8
2.0.0.pre.rc9
2.0.1
2.1.0
2.2.0
2.2.0.pre.rc1
2.2.1
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.1
2.7.1.1
2.7.2
2.7.2.1
Fixed in
2.7.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.2
patch
1 CVE
CVE-2023-28846
GHSA-m875-3xf6-mf78
Mar 30, 2023
unpoly-rails Denial of Service vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
There is a possible Denial of Service (DoS) vulnerability in the unpoly-rails gem that implements the Unpoly server protocol for Rails applications. ImpactThis issues affects Rails applications that operate as an upstream of a load balancer's that uses passive health checks. The unpoly-rails gem echoes the request URL as an If the response header is too large to be parsed by a load balancer downstream of the Rails application, it may cause the load balancer to remove the upstream from a load balancing group. This causes that application instance to become unavailable until a configured timeout is reached or until an active healthcheck succeeds. PatchesThe fixed release 2.7.2.2+ is available via RubyGems and GitHub. WorkaroundsIf you cannot upgrade to a fixed release, several workarounds are available:
Affected versions
0.20.0
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.25.0
0.25.1
0.25.2
0.26.0
0.26.1
+ 89 more Show less
0.26.2
0.27.0
0.27.1
0.27.2
0.27.3
0.28.0
0.28.1
0.29.0
0.30.0
0.30.1
0.31.0
0.31.1
0.31.2
0.32.0
0.33.0
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.36.0
0.36.1
0.36.2
0.37.0
0.50.0
0.50.1
0.50.2
0.51.0
0.51.1
0.52.0
0.53.0
0.53.1
0.53.2
0.53.3
0.53.4
0.54.0
0.54.1
0.55.0
0.55.1
0.56.0
0.56.1
0.56.2
0.56.3
0.56.4
0.56.5
0.56.6
0.56.7
0.57.0
0.60.0
0.60.1
0.60.2
0.60.3
0.61.0
0.61.1
0.62.0
0.62.1
1.0.0
1.0.1
1.0.3
2.0.0
2.0.0.pre.rc10
2.0.0.pre.rc11
2.0.0.pre.rc2
2.0.0.pre.rc3
2.0.0.pre.rc4
2.0.0.pre.rc5
2.0.0.pre.rc6
2.0.0.pre.rc7
2.0.0.pre.rc8
2.0.0.pre.rc9
2.0.1
2.1.0
2.2.0
2.2.0.pre.rc1
2.2.1
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.1
2.7.1.1
2.7.2
2.7.2.1
Fixed in
2.7.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.0.rc2
pre
| ||
3.0.0.rc1
pre
|