PT-2025-12122 · Llava · Llava

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-12070

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions haotian-liu/llava version 1.2.0
Description A Denial of Service (DoS) issue exists in the file upload feature due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users. This issue can be exploited without authentication.
Recommendations For version 1.2.0, consider restricting access to the file upload feature until a patch is available to prevent exploitation. As a temporary workaround, limit the size of filenames that can be uploaded to prevent the server from becoming overwhelmed.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12070

Affected Products

Llava