Danswer Denial-of-Service Vulnerability via Malformed Multipart Boundary
Vulnerability
A denial-of-service vulnerability has been identified in danswer-ai/danswer version 0.3.94. The issue arises when an attacker uploads a file with a malformed multipart boundary, specifically by adding an excessive number of characters to the end of the boundary. This causes the server to continuously process each character, leading to application unavailability. The vulnerability can be exploited by sending a single crafted request, impacting all users on the server.
Impact
Exploitation of this vulnerability causes a denial-of-service condition, making the application inaccessible to users.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.7remediation
0.0relevance
0.0threat
6.4urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
