CVE-2024-10821
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-10821 is a Denial of Service (DoS) vulnerability affecting the Invoke-AI server version v5.0.1. Unauthenticated attackers can exploit this issue by appending excessive characters to the end of multipart boundaries in requests to the `/api/v1/images/upload` endpoint. The server fails to handle such requests appropriately, leading to an infinite loop and a complete denial of service for all users. This vulnerability allows attackers to cause excessive resource consumption, making the server unavailable to legitimate users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.