Denial of Service Vulnerability in OctoPrint by OctoPrint
CVE-2025-48879
6.5MEDIUM
What is CVE-2025-48879?
Versions of OctoPrint prior to 1.11.2 are susceptible to a denial of service attack, allowing unauthenticated adversaries to send a malformed multipart/form-data request. This can cause the server to enter an infinite loop, becoming unresponsive as the request handler fails to locate the requested parts of an incomplete upload. The single-threaded nature of Tornado exacerbates the issue, effectively halting the entire web server. Users are encouraged to upgrade to version 1.11.2 or later to mitigate this vulnerability.
Affected Version(s)
OctoPrint < 1.11.2