---
id: CVE-2025-48879
aliases:
  - GHSA-9wj4-8h85-pgrw
  - PYSEC-2026-1713
title: >-
  OctoPrint Vulnerable to Denial of Service through malformed HTTP request in
  OctoPrint
summary: >-
  OctoPrint Vulnerable to Denial of Service through malformed HTTP request in
  OctoPrint
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: octoprint
product: octoprint
ecosystem: pip
affected:
  - octoprint < 1.11.2
patched:
  - octoprint 1.11.2
published: '2025-06-10'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9wj4-8h85-pgrw'
references:
  - url: >-
      https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-9wj4-8h85-pgrw
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48879'
  - url: >-
      https://github.com/OctoPrint/OctoPrint/commit/c9c35c17bd820f19c6b12e6c0359fc0cfdd0c1ec
  - url: 'https://github.com/OctoPrint/OctoPrint'
tags:
  - osv
  - pip
epss: 0.00256
epssPercentile: 0.17553
ingestedAt: '2026-07-08T18:25:48.107Z'
---

## Overview

### Impact

OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken `multipart/form-data` request to OctoPrint and through that make the web server component become unresponsive. This could be used to effectively run a denial of service attack on the OctoPrint server.

### Patches

The vulnerability has been patched in version 1.11.2.

### Workaround

OctoPrint administrators are once more reminded to not make OctoPrint available on hostile networks (e.g. the internet), regardless of whether this vulnerability is patched or not.

### Details

The issue can be triggered by a broken `multipart/form-data` request lacking an end boundary to any of OctoPrint's endpoints implemented through the `octoprint.server.util.tornado.UploadStorageFallbackHandler` request handler. The request handler will get stuck in an endless busy loop, looking for a part of the request that will never come. As Tornado is single-threaded, that will effectively block the whole web server.

The fix adds detection of invalid requests like that and ensures they are handled gracefully with an HTTP 400 Bad Request response.

### Credits

This vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi.

## Affected packages

- `octoprint < 1.11.2`

## Remediation

Upgrade to a patched release:

- `octoprint 1.11.2`
