A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large filename, causing the server to become overwhelmed and unavailable for legitimate users. This attack does not require authentication, making it highly scalable and increasing the risk of exploitation.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 01 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Youdao Youdao qanything | |
| CPEs | cpe:2.3:a:youdao:qanything:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products | Qanything Qanything qanything | Youdao Youdao qanything | 
Thu, 31 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Qanything Qanything qanything | |
| CPEs | cpe:2.3:a:qanything:qanything:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products | Qanything Qanything qanything | 
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large filename, causing the server to become overwhelmed and unavailable for legitimate users. This attack does not require authentication, making it highly scalable and increasing the risk of exploitation. | |
| Title | Unauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanything | |
| Weaknesses | CWE-400 | |
| References |  | |
| Metrics | cvssV3_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:47.575Z
Updated: 2025-03-20T18:16:36.810Z
Reserved: 2024-12-20T19:00:30.904Z
Link: CVE-2024-12864
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-20T17:50:50.970Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-03-20T10:15:30.720
Modified: 2025-08-01T10:51:13.763
Link: CVE-2024-12864
 Redhat
                        Redhat
                    No data.