CVE-2024-12070
Denial of Service in haotian-liu/llava
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users. This issue can be exploited without authentication, making it highly scalable and increasing the risk of exploitation.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
haotian-liu · haotian-liu/llavaWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →