ZeroHour

CVE-2024-12388

PoC
CVSS 3.0
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inputs. This allows an attacker to send a small malicious payload to the server, causing it to become unresponsive and unable to handle any requests from other users.

Vendors
binary-husky
Products
gpt academic
Weakness
CWE-1333
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.