PT-2025-12276 · Zenml · Zenml

Published

2025-03-20

·

Updated

2025-07-15

·

CVE-2024-9340

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions zenml version 0.66.0
Description A Denial of Service (DoS) vulnerability allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected API endpoints include /api/v1/login and /api/v1/device authorization.
Recommendations zenml version 0.66.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9340
GHSA-6GMF-2369-C76C
PYSEC-2025-57

Affected Products

Zenml