We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-10907

Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat



Description

In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite loop, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.

Reserved 2024-11-05 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Any version
affected

References

huntr.com/bounties/bf3ca81d-3508-4455-95d9-0b653e46d6e4

cve.org (CVE-2024-10907)

nvd.nist.gov (CVE-2024-10907)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-10907

Support options

Helpdesk Chat, Email, Knowledgebase