
1/6/2024

30/1/2025
CVE-2024-4148: Redos (Regular Expression Denial of Service) in lunary-ai/lunary
First published: Sat Jun 01 2024(Updated: )
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the response time of the application and potentially render it completely non-functional. Specifically, the vulnerability can be triggered by sending a specially crafted request to the application, leading to a denial of service where the application crashes.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|
lunary lunary | =1.2.10 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2024-4148?
CVE-2024-4148 is classified as a Regular Expression Denial of Service (ReDoS) vulnerability.
How do I fix CVE-2024-4148?
To fix CVE-2024-4148, update the lunary application to a version that addresses the ReDoS vulnerability.
What application is affected by CVE-2024-4148?
CVE-2024-4148 affects the lunary-ai/lunary application, specifically version 1.2.10.
What impact does CVE-2024-4148 have on the application?
CVE-2024-4148 can significantly degrade the response time of the application when exploited.
Can I exploit CVE-2024-4148 without logging in?
Exploitation of CVE-2024-4148 can potentially be done remotely by manipulating regular expressions, making authentication unnecessary.
- agent/title
- agent/description
- agent/type
- agent/first-publish-date
- agent/author
- agent/event
- collector/epss-latest
- source/FIRST
- agent/epss
- agent/weakness
- agent/severity
- agent/softwarecombine
- agent/source
- collector/mitre-cve
- source/MITRE
- agent/last-modified-date
- agent/references
- agent/tags
- collector/nvd-api
- source/NVD
- vendor/lunary
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203