CVE-2024-10935

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-10935 is a denial-of-service vulnerability affecting version 1.10.0 of automatic1111/stable-diffusion-webui. The flaw arises when the server encounters excessive characters appended to the end of multipart boundaries in malformed requests. An attacker can exploit this issue by sending such requests, leading to excessive resource consumption and a complete denial of service for all users. Notably, this vulnerability is unauthenticated, meaning no user login or interaction is needed for an attacker to exploit it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share