Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7007 | BentoML vulnerable to Uncontrolled Resource Consumption |
No reference.
Tue, 15 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In bentoml/bentoml version 1.3.9, the `/login` endpoint of the newly integrated Gradio app is vulnerable to a Denial of Service (DoS) attack. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction. | ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8966. Notes: All CVE users should reference CVE-2024-8966 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage. |
| Title | Denial of Service (DoS) via Multipart Boundary in bentoml/bentoml | |
| Weaknesses | CWE-400 | |
| References |
|
|
| Metrics |
cvssV3_0
|
Thu, 20 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In bentoml/bentoml version 1.3.9, the `/login` endpoint of the newly integrated Gradio app is vulnerable to a Denial of Service (DoS) attack. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction. | |
| Title | Denial of Service (DoS) via Multipart Boundary in bentoml/bentoml | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2025-04-15T15:54:10.390Z
Reserved: 2024-12-18T18:06:22.125Z
Link: CVE-2024-12759
Updated:
Status : Rejected
Published: 2025-03-20T10:15:29.630
Modified: 2025-04-15T16:15:21.733
Link: CVE-2024-12759
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD