Safety vulnerability ID: 76279
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the lm-sys FastChat package are vulnerable to Denial of Service (DoS). The file upload feature fails to properly validate the length of filenames in multipart form-data requests, leading to server resource exhaustion. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request with an excessively large filename in the form-data boundary, resulting in the server becoming overwhelmed and unavailable to legitimate users.
Latest version: 0.2.36
An open platform for training, serving, and evaluating large language model based chatbots.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application