CVE-2024-10714

A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing each character and displaying warnings, rendering the application inaccessible. The issue occurs when the terminal shows a warning: 'multipart.multipart Consuming a byte '0x2d' in end state'.
References
Link Resource
https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*

History

15 Jul 2025, 16:46

Type Values Removed Values Added
References () https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 - () https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068 - Exploit, Third Party Advisory
CPE cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
First Time Binary-husky
Binary-husky gpt Academic
Summary
  • (es) Una vulnerabilidad en binary-husky/gpt_academic versión 3.83 permite a un atacante provocar una denegación de servicio (DoS) añadiendo caracteres excesivos al final de un límite multiparte durante la carga de un archivo. Esto provoca que el servidor procese continuamente cada carácter y muestre advertencias, lo que hace que la aplicación sea inaccesible. El problema ocurre cuando la terminal muestra la advertencia: «multipart.multipart Consuming a byte '0x2d' in end state».

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 16:46


NVD link : CVE-2024-10714

Mitre link : CVE-2024-10714

CVE.ORG link : CVE-2024-10714


JSON object : View

Products Affected

binary-husky

  • gpt_academic
CWE
CWE-400

Uncontrolled Resource Consumption