CVE-2024-10907

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-10907 is a newly disclosed vulnerability affecting the lm-sys/fastchat server in Release v0.2.36. This issue arises when the server fails to manage excessive characters added to the end of multipart boundaries. An attacker can exploit this flaw by sending malformed multipart requests with extra characters at the boundary's end. These extra characters trigger an infinite loop, causing excessive resource consumption and a Denial of Service (DoS) for all users. Notably, this vulnerability is unauthenticated, allowing an attacker to exploit it without requiring user login or interaction.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share