A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the /api/v1/state endpoint of LightningApp. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.
An exception is thrown from a function, but it is not caught.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Pytorch_lightning | Lightningai | 2.3.2 (including) | 2.3.2 (including) |