CVE-2024-12864

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-12864 is a newly discovered Denial of Service (DoS) vulnerability affecting the file upload feature of netease-youdao/qanything version v2.0.0. The issue arises from the server's improper handling of form-data with oversized filenames in upload requests. An attacker can exploit this vulnerability by sending a large filename, leading the server to become overloaded and unresponsive, denying service to legitimate users. No authentication is required for this attack, thereby increasing the threat's scalability and the likelihood of successful exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share