Skip to content
InvokeAIGHSA-6f6x-f56q-5xgv

InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`

High7.5CVE-2024-10821 · Published Mar 20, 2025 · updated Jul 7, 2026

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and a complete denial of service for all users. The affected endpoint is `/api/v1/images/upload`.

GitHub advisory

Affected versions

PackageAffectedFixed in
invokeai
PyPI
<= 5.0.2No fix yet
Details and references

More InvokeAI advisories

All InvokeAI
Advisory
InvokeAI has External Control of File Name or Path
Critical9.8Sep 18, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical9.8Mar 21, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical9.1Mar 20, 2025
InvokeAI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.