Back to search
CVE-2022-44566
Published: Feb 9, 2023
Modified: Mar 25, 2025
PUBLISHED
Description
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan resulting in potential Denial of Service.
| Vendor | Product | Versions |
|---|---|---|
n/a | https://github.com/rails/rails | affected 7.0.4.1, 6.1.7.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now