CVE-2024-10225

A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible.
References
Link Resource
https://huntr.com/bounties/cd793f83-f122-432b-83e7-1cc8c78817b7 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hliu:llava:1.2.0:*:*:*:*:*:*:*

History

11 Jul 2025, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:hliu:llava:1.2.0:*:*:*:*:*:*:*
First Time Hliu llava
Hliu
Summary
  • (es) Una vulnerabilidad en haotian-liu/llava v1.2.0 permite a un atacante provocar una denegación de servicio (DoS) añadiendo una gran cantidad de caracteres al final de un límite multiparte en una solicitud de carga de archivos. Esto provoca que el servidor procese continuamente cada carácter, lo que hace que la aplicación sea inaccesible.
References () https://huntr.com/bounties/cd793f83-f122-432b-83e7-1cc8c78817b7 - () https://huntr.com/bounties/cd793f83-f122-432b-83e7-1cc8c78817b7 - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-11 20:41


NVD link : CVE-2024-10225

Mitre link : CVE-2024-10225

CVE.ORG link : CVE-2024-10225


JSON object : View

Products Affected

hliu

  • llava
CWE
CWE-400

Uncontrolled Resource Consumption