CVE-2024-9340

HIGH

Zenml < 0.68.0 - Infinite Loop

Title source: rule
STIX 2.1

Description

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`.

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (2)
pypi/zenml 0 - 0.68.0PyPI
zenml/zenml < 0.68.0
Published Mar 20, 2025
Tracked Since Feb 18, 2026