PT-2025-12023 · Realchar · Realchar

Published

2025-03-20

·

Updated

2025-12-10

·

CVE-2024-10051

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Realchar version v0.0.4
Description The issue is an unauthenticated denial of service (DoS) attack that exists in the file upload request handling. By appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request, the server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. This issue impacts all users of the service and does not require any user interaction.
Recommendations For Realchar version v0.0.4, consider restricting or validating the file upload request handling to prevent excessive resource consumption. As a temporary workaround, restrict access to the file upload functionality until a patch is available.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-10051

Affected Products

Realchar