CVE-2024-12074

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-12074 is a Denial of Service (DoS) vulnerability affecting automatic1111/stable-diffusion-webui version 1.10.0. The issue stems from improper handling of form-data with unusually large filenames during file upload requests. A malicious actor can exploit this vulnerability by sending a payload with an excessively long filename, leading the server to become overwhelmed and unresponsive. This DoS attack can be executed without requiring authentication, making it highly scalable and increasing the likelihood of successful exploitation. Legitimate users may experience unavailability as a result.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share