Regular Expression Denial of Service in Lunary by Lunary AI
CVE-2024-8998
What is CVE-2024-8998?
A Regular Expression Denial of Service vulnerability in Lunary by Lunary AI can be exploited by sending specially crafted user input to the server. The regex pattern used for matching, /{.*?}/, can lead to significant server delays while processing certain inputs due to its polynomial time complexity in the default JavaScript regex engine. This allows attackers to disrupt services by causing the server to hang for an arbitrary amount of time. An update to version 1.4.26 addresses this issue, enhancing the product's resilience against such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.4.26
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
