Intel

AIKIDO-2026-855506

ransack is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-j3f8-w227-4hh8 Published 5 days ago

75

High Risk

This Affects:

RUBYransack
0.1.0 - 4.4.2
Fixed in 4.4.3
5.0.0 - 5.0.1
Fixed in 5.0.2
Are you affected? Scan for Free

TL;DR

A search key is processed in Ransack::Context#association_path in quadratic time based on how many _ separated segments it has, and Rack has no length limit on a query parameter key, so the segment count comes from untrusted input. Each segment causes a linear length segments.join("_") rebuild plus a regex match, so a key with thousands of segments burns seconds of CPU on a worker. A handful of concurrent requests against any endpoint that calls ransack exhausts the worker pool, leading to unauthenticated denial of service. The fix caps key depth at Constants::MAX_KEY_DEPTH and rejects keys that exceed that depth before parsing begins.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ransack is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 4.4.2 and 5.0.0 - 5.0.1.

How to fix this

Upgrade the ransack library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform