CVE-2024-8764
HIGHlunary < 1.4.23 - Denial of Service via Inefficient Regular Expression Complexity
Title source: llmDescription
A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking the server from processing other requests.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/088c04a1-d23a-47f2-9d7c-b84d7332868d
Scores
CVSS v3
7.5
EPSS
0.0071
EPSS Percentile
48.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (1)
lunary/lunary
< 1.4.23
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026