Activerecordproject Activerecord
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Activerecordproject Activerecord.
By the Year
In 2026 there have been 0 vulnerabilities in Activerecordproject Activerecord. Activerecord did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 2 | 8.15 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Activerecord vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Activerecordproject Activerecord Security Vulnerabilities
SQLi via Unsanitized Comments in Rails ActiveRecord <6.0.6.1, 6.1.7.1, 7.0.4.1
CVE-2023-22794
8.8 - High
- February 09, 2023
A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious user input is passed to either the `annotate` query method, the `optimizer_hints` query method, or through the QueryLogs interface which automatically adds annotations, it may be sent to the database withinsufficient sanitization and be able to inject SQL outside of the comment.
SQL Injection
Rails ActiveRecord PostgreSQL Adapter DoS <7.0.4.1 / <6.1.7.1
CVE-2022-44566
7.5 - High
- February 09, 2023
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan resulting in potential Denial of Service.
ActiveRecord YAML Serialized Columns RCE Escalation (v<7.0.3.1,<6.1.6.1,<6.0.5.1,<5.2.8.1)
CVE-2022-32224
9.8 - Critical
- December 05, 2022
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.
Marshaling, Unmarshaling
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Activerecordproject Activerecord or by Activerecordproject? Click the Watch button to subscribe.