CVE-2024-10225
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-10225 is a newly disclosed vulnerability affecting the haotian-liu/llava library version 1.2.0. An attacker can exploit this issue by sending a file upload request with a specially crafted boundary, appending an excessively large number of characters. This causes the server to become bogged down in processing each character, resulting in a Denial of Service (DoS) attack and rendering the application inaccessible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LLaVA