Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. activerecord
  4. ›
  5. CVE-2022-44566

CVE-2022-44566: Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter

January 18, 2023 (updated January 15, 2026)

There is a potential denial of service vulnerability present in ActiveRecord’s PostgreSQL adapter.

This has been assigned the CVE identifier CVE-2022-44566.

Versions Affected: All. Not affected: None.

References

  • code.jeremyevans.net/2022-11-01-forcing-sequential-scans-on-postgresql.html
  • discuss.rubyonrails.org/t/cve-2022-44566-possible-denial-of-service-vulnerability-in-activerecords-postgresql-adapter/82119
  • github.com/advisories/GHSA-579w-22j4-4749
  • github.com/rails/rails
  • github.com/rails/rails/commit/4f44aa9d514e701ada92b5cf08beccf566eeaebf
  • github.com/rails/rails/commit/82bcdc011e2ff674e7dd8fd8cee3a831c908d29b
  • github.com/rails/rails/releases/tag/v6.1.7.1
  • github.com/rails/rails/releases/tag/v7.0.4.1
  • github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2022-44566.yml
  • mailchi.mp/railslts/rails-lts-multiple-dos-vulnerabilities-in-rails-rack-and-globalid
  • makandracards.com/railslts/508019-rails-5-2-lts-changelog
  • nvd.nist.gov/vuln/detail/CVE-2022-44566
  • rubyonrails.org/2023/1/17/Rails-Versions-6-0-6-1-6-1-7-1-7-0-4-1-have-been-released

Code Behaviors & Features

Detect and mitigate CVE-2022-44566 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.1.7.1, all versions starting from 7.0.0 before 7.0.4.1

Fixed versions

  • 6.1.7.1
  • 7.0.4.1

Solution

Upgrade to versions 6.1.7.1, 7.0.4.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

gem/activerecord/CVE-2022-44566.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:36:25 +0000.