CVE-2024-10912High· 7.5▾ TwilightFastChat Denial of Service vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable to legitimate users.
fschat <= 0.2.36Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2024-10907High· 7.5FastChat Uncontrolled Resource Consumption vulnerability
CVE-2024-11603High· 7.5FastChat Server-Side Request Forgery vulnerability
CVE-2024-12376High· 7.5FastChat Server-Side Request Forgery vulnerability
CVE-2024-10908Medium· 6.1FastChat open redirect vulnerability