CVE-2024-8789

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-8789 is a newly identified vulnerability affecting Lunary-ai's Lunary application, specifically version git 105a3f6. This issue involves a Regular Expression Denial of Service (ReDoS) weakness. The application enables users to submit their custom regular expressions, which are executed on the server side. Maliciously crafted regular expressions can exhibit exponential runtime complexity based on input size, leading to denial of service attacks. An attacker can exploit this by submitting a specially designed regular expression, causing the server to become unresponsive for an extended period.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share