CVE-2024-12388
MEDIUMbinary-husky gpt_academic 310122f - Regular Expression Denial of Service via User Input Parsing
Title source: llmDescription
A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inputs. This allows an attacker to send a small malicious payload to the server, causing it to become unresponsive and unable to handle any requests from other users.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/b1c01c94-e477-41db-9d17-601aa25e351c
Scores
CVSS v3
6.5
EPSS
0.0062
EPSS Percentile
45.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (1)
binary-husky/gpt_academic
2024-10-15
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026