ransack is vulnerable to Denial of Service (DoS)
75
High Risk
A search key is processed in Ransack::Context#association_path in quadratic time based on how many _ separated segments it has, and Rack has no length limit on a query parameter key, so the segment count comes from untrusted input. Each segment causes a linear length segments.join("_") rebuild plus a regex match, so a key with thousands of segments burns seconds of CPU on a worker. A handful of concurrent requests against any endpoint that calls ransack exhausts the worker pool, leading to unauthenticated denial of service. The fix caps key depth at Constants::MAX_KEY_DEPTH and rejects keys that exceed that depth before parsing begins.
You are affected if you are using a version that falls within the vulnerable range.
ransack is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 4.4.2 and 5.0.0 - 5.0.1.
Upgrade the ransack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.