Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f6x-f56q-5xgv

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

InvokeAI has Denial of Service (DoS) vulnerability in /api/v1/images/upload

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and a complete denial of service for all users. The affected endpoint is /api/v1/images/upload.

Пакеты

Наименование

InvokeAI

pip
Затронутые версииВерсия исправления

<= 5.0.2

Отсутствует

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and a complete denial of service for all users. The affected endpoint is `/api/v1/images/upload`.

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835