CVE-2024-10714

A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing each character and displaying warnings, rendering the application inaccessible. The issue occurs when the terminal shows a warning: 'multipart.multipart Consuming a byte '0x2d' in end state'.
References
Link Resource
https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*

History

15 Jul 2025, 16:46

Type Values Removed Values Added
References () https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 - () https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 - Exploit, Third Party Advisory
CPE cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad en binary-husky/gpt_academic versión 3.83 permite a un atacante provocar una denegación de servicio (DoS) añadiendo caracteres excesivos al final de un límite multiparte durante la carga de un archivo. Esto provoca que el servidor procese continuamente cada carácter y muestre advertencias, lo que hace que la aplicación sea inaccesible. El problema ocurre cuando la terminal muestra la advertencia: «multipart.multipart Consuming a byte '0x2d' in end state».
First Time Binary-husky gpt Academic
Binary-husky

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 16:46


NVD link : CVE-2024-10714

Mitre link : CVE-2024-10714

CVE.ORG link : CVE-2024-10714


JSON object : View

Products Affected

binary-husky

  • gpt_academic
CWE
CWE-400

Uncontrolled Resource Consumption