id: PYSEC-2026-1290 published: "2026-07-07T14:34:51.831072Z" modified: "2026-07-07T17:23:59.609331Z" aliases: - CVE-2024-10829 - GHSA-6xgj-c5fx-5v57 summary: DB-GPT Uncontrolled Resource Consumption vulnerability details: A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. affected: - package: name: dbgpt ecosystem: PyPI purl: pkg:pypi/dbgpt ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 0.6.0 versions: - 0.4.7 - 0.5.0 - 0.5.1 - 0.5.10 - 0.5.1rc0 - 0.5.2 - 0.5.2rc0 - 0.5.3 - 0.5.3rc0 - 0.5.4 - 0.5.4rc0 - 0.5.5 - 0.5.5rc0 - 0.5.6 - 0.5.6rc0 - 0.5.7 - 0.5.7rc0 - 0.5.8 - 0.5.9 - 0.5.9rc0 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-10829 - type: PACKAGE url: https://github.com/eosphoros-ai/DB-GPT - type: WEB url: https://huntr.com/bounties/e3a4a0ad-a2e0-497f-a2e0-e3c0ec7c4de4 - type: PACKAGE url: https://pypi.org/project/dbgpt - type: ADVISORY url: https://github.com/advisories/GHSA-6xgj-c5fx-5v57 severity: - type: CVSS_V3 score: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H