Back

HIGH

Denial of Service (DoS) Vulnerability in mintplex-labs/anything-llm

Published Apr 10, 2024

Description

A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware with a specially crafted 'Authorization:' header. This vulnerability leads to uncontrolled resource consumption, causing a DoS condition.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner @huntr_ai
Published Apr 10, 2024
Updated Aug 1, 2024
Reserved Apr 10, 2024

CISA Vulnrichment

Updated Apr 10, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner @huntr_ai
Published Apr 10, 2024
Updated Aug 1, 2024

GitHub

No data