Denial of Service Vulnerability in OctoPrint by OctoPrint
CVE-2025-48879

6.5MEDIUM

Key Information:

Vendor

Octoprint

Status
Vendor
CVE Published:
10 June 2025

What is CVE-2025-48879?

Versions of OctoPrint prior to 1.11.2 are susceptible to a denial of service attack, allowing unauthenticated adversaries to send a malformed multipart/form-data request. This can cause the server to enter an infinite loop, becoming unresponsive as the request handler fails to locate the requested parts of an incomplete upload. The single-threaded nature of Tornado exacerbates the issue, effectively halting the entire web server. Users are encouraged to upgrade to version 1.11.2 or later to mitigate this vulnerability.

Affected Version(s)

OctoPrint < 1.11.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.