CVE-2024-10907
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-10907 is a newly disclosed vulnerability affecting the lm-sys/fastchat server in Release v0.2.36. This issue arises when the server fails to manage excessive characters added to the end of multipart boundaries. An attacker can exploit this flaw by sending malformed multipart requests with extra characters at the boundary's end. These extra characters trigger an infinite loop, causing excessive resource consumption and a Denial of Service (DoS) for all users. Notably, this vulnerability is unauthenticated, allowing an attacker to exploit it without requiring user login or interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.