CVE-2025-0182

A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sending multiple requests to the /auth/saml/callback endpoint, leading to uncontrolled memory consumption and eventual denial of service.
Configurations

No configuration.

History

15 Oct 2025, 13:16

Type Values Removed Values Added
CWE CWE-400 CWE-770
Summary
  • (es) Una vulnerabilidad en danswer-ai/danswer versión 0.9.0 permite la denegación de servicio por agotamiento de memoria. El problema surge del uso de una versión vulnerable del paquete starlette (&lt;=0.49) a través de fastapi, parcheada en fastapi versión 0.115.3. Esta vulnerabilidad puede explotarse enviando múltiples solicitudes al endpoint /auth/saml/callback, lo que provoca un consumo descontrolado de memoria y, finalmente, la denegación de servicio.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-10-15 13:16


NVD link : CVE-2025-0182

Mitre link : CVE-2025-0182

CVE.ORG link : CVE-2025-0182


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling