PT-2025-12051 · Unknown+1 · Chuanhuchatgpt+1
Published
2025-03-20
·
Updated
2025-07-14
·
CVE-2024-10650
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ChuanhuChatGPT version 20240918
Description
A Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for a previous issue, the problem can still be exploited by sending data in groups of 10 characters per line, with multiple lines. This can cause the system to continuously process these characters, resulting in prolonged unavailability of the service. The exploitation now requires low privilege if authentication is enabled due to a version upgrade in Gradio.
Recommendations
As a temporary workaround, consider restricting the size of data payloads that can be sent to the system to prevent exploitation.
Restrict access to the multipart boundary feature to minimize the risk of exploitation.
Avoid sending data in groups of 10 characters per line, with multiple lines, until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chuanhuchatgpt
Gradio