Skip to content
ZenMLGHSA-6gmf-2369-c76c

ZenML unauthenticated DoS via Multipart Boundry

High7.5CVE-2024-9340 · Published Mar 20, 2025 · updated Jun 30, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.68.00.68.0
Details and references

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-835
Also known as
CVE-2024-9340, PYSEC-2025-57

More ZenML advisories

All ZenML
DateAdvisory
Nov 142024Missing ratelimit on passwrod resets in zenml
CVE-2024-4311Medium5.4fixed in 0.57.0rc2
Oct 52025ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
CVE-2025-8406Medium6.3fixed in 0.84.2
Jun 302024Reflected Cross-Site Scripting (XSS) in zenml
CVE-2024-5062Medium6.1fixed in 0.58.0
Jun 242024Improper line feed handling in zenml
CVE-2024-4460Medium4.3fixed in 0.57.1
Jun 82024zenml-io/zenml does not expire the session after password reset
CVE-2024-4680Low3.9no fix yet
Jun 62024Improper authorization in zenml
CVE-2024-2035Medium6.5fixed in 0.56.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.