Danswer Denial-of-Service Vulnerability via Malformed Multipart Boundary

Vulnerability

A denial-of-service vulnerability has been identified in danswer-ai/danswer version 0.3.94. The issue arises when an attacker uploads a file with a malformed multipart boundary, specifically by adding an excessive number of characters to the end of the boundary. This causes the server to continuously process each character, leading to application unavailability. The vulnerability can be exploited by sending a single crafted request, impacting all users on the server.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, making the application inaccessible to users.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.