Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-7049 | In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite loop, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue. | 
  Github GHSA | 
                GHSA-qg86-f892-m4hj | FastChat Uncontrolled Resource Consumption vulnerability | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-400 | 
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-835 | 
Thu, 31 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Lm-sys
         Lm-sys fastchat  | 
|
| CPEs | cpe:2.3:a:lm-sys:fastchat:0.2.36:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Lm-sys
         Lm-sys fastchat  | 
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite loop, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue. | |
| Title | Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat | |
| Weaknesses | CWE-400 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-15T12:50:14.123Z
Reserved: 2024-11-05T22:25:53.642Z
Link: CVE-2024-10907
Updated: 2025-03-20T17:52:02.243Z
Status : Modified
Published: 2025-03-20T10:15:21.357
Modified: 2025-10-15T13:15:37.713
Link: CVE-2024-10907
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA