CVE-2024-8028
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-8028 is a newly disclosed vulnerability in the danswer-ai/danswer library version 0.3.94. An attacker can exploit this issue by uploading a file with a malformed multipart boundary, triggering a Denial of Service (DoS) condition. This occurs when the server continuously processes each character at the end of the boundary, leading to resource exhaustion and rendering the application inaccessible. The vulnerability can be exploited with a single crafted request, impacting all users on the affected server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.