VDB
Sign up
HIGH7.5

GHSA-98m9-hrrm-r99r

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

Quick fix

GHSA-98m9-hrrm-r99r — faraday: upgrade to the fixed version with the command below.

bundle update faraday

Details

`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.

A crafted query string such as:

```text a[x][x][x][x]...[x]=1 ```

causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths.

This has been patched in version 2.14.3 and backported to 1.10.6.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/faraday
Introduced in: 2.0.0Fixed in: 2.14.3
Fixbundle update faraday
RubyGems/faraday
Introduced in: 1.0.0Fixed in: 1.10.6
Fixbundle update faraday

References