CVE Vulnerabilities

CVE-2024-12387

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Mar 20, 2025 | Modified: Oct 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issue arises due to improper input validation when handling compressed file uploads.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

Name Vendor Start Version End Version
Gpt_academic Binary-husky 2024-10-15 (including) 2024-10-15 (including)

References