Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10714— Denial of Service in binary-husky/gpt_academic

EPSS 0.27% · P51
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-10714

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial of Service in binary-husky/gpt_academic
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing each character and displaying warnings, rendering the application inaccessible. The issue occurs when the terminal shows a warning: 'multipart.multipart Consuming a byte '0x2d' in end state'.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
不加限制或调节的资源分配
Source: NVD (National Vulnerability Database)
Vulnerability Title
GPT Academic 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic 3.83版本存在资源管理错误漏洞,该漏洞源于文件上传时多部分边界末尾的过多字符导致服务器持续处理每个字符并显示警告,从而使应用程序无法访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
binary-huskybinary-husky/gpt_academic unspecified ~ latest -

II. Public POCs for CVE-2024-10714

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-10714

登录查看更多情报信息。

Same Patch Batch · binary-husky · 2025-03-20 · 20 CVEs total

CVE-2024-11030SSRF in binary-husky/gpt_academic
CVE-2024-10948Arbitrary File Read via Upload Function in binary-husky/gpt_academic
CVE-2024-10954Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`
CVE-2024-10812Open Redirect in binary-husky/gpt_academic
CVE-2024-10819CSRF to XSS in binary-husky/gpt_academic
CVE-2024-10956Cross-Site WebSocket Hijacking in binary-husky/gpt_academic
CVE-2024-10950Code Injection in binary-husky/gpt_academic
CVE-2024-10986Local File Read (LFI) by Tarslip Symlink via arxiv_download() API in binary-husky/gpt_acad
CVE-2024-11039Deserialization of Untrusted Data in binary-husky/gpt_academic
CVE-2024-11033Denial of Service (DoS) in binary-husky/gpt_academic
CVE-2025-0183Stored XSS in binary-husky/gpt_academic
CVE-2024-11031SSRF in binary-husky/gpt_academic
CVE-2024-11037Path Traversal in binary-husky/gpt_academic
CVE-2024-12392Server-Side Request Forgery (SSRF) in binary-husky/gpt_academic
CVE-2024-12391Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12387Improper Input Validation in binary-husky/gpt_academic
CVE-2024-12389Path Traversal in binary-husky/gpt_academic
CVE-2024-12388Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12390Remote Code Execution in binary-husky/gpt_academic

IV. Related Vulnerabilities

V. Comments for CVE-2024-10714

No comments yet


Leave a comment