CVE-2024-12388

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inputs. This allows an attacker to send a small malicious payload to the server, causing it to become unresponsive and unable to handle any requests from other users.
References
Link Resource
https://huntr.com/bounties/b1c01c94-e477-41db-9d17-601aa25e351c Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*

History

31 Jul 2025, 17:54

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en binary-husky/gpt_academic versión 310122f permite un ataque de denegación de servicio por expresión regular (ReDoS). La aplicación utiliza una expresión regular para analizar la entrada del usuario, lo que puede tardar un tiempo polinomial en coincidir con ciertas entradas manipuladas. Esto permite a un atacante enviar una pequeña carga maliciosa al servidor, lo que provoca que deje de responder y no pueda gestionar las solicitudes de otros usuarios.
CPE cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*
References () https://huntr.com/bounties/b1c01c94-e477-41db-9d17-601aa25e351c - () https://huntr.com/bounties/b1c01c94-e477-41db-9d17-601aa25e351c - Exploit, Third Party Advisory
First Time Binary-husky gpt Academic
Binary-husky

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-31 17:54


NVD link : CVE-2024-12388

Mitre link : CVE-2024-12388

CVE.ORG link : CVE-2024-12388


JSON object : View

Products Affected

binary-husky

  • gpt_academic
CWE
CWE-115

Misinterpretation of Input