ZenMLGHSA-6gmf-2369-c76c
ZenML unauthenticated DoS via Multipart Boundry
High7.5CVE-2024-9340 · Published Mar 20, 2025 · updated Jun 30, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.68.0 | 0.68.0 |
Details and references
A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`.
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 142024 | Missing ratelimit on passwrod resets in zenml CVE-2024-4311Medium5.4fixed in 0.57.0rc2 | Medium5.4 | 0.57.0rc2 |
| Oct 52025 | ZenML is vulnerable to Path Traversal through its `PathMaterializer` class CVE-2025-8406Medium6.3fixed in 0.84.2 | Medium6.3 | 0.84.2 |
| Jun 302024 | Reflected Cross-Site Scripting (XSS) in zenml CVE-2024-5062Medium6.1fixed in 0.58.0 | Medium6.1 | 0.58.0 |
| Jun 242024 | Improper line feed handling in zenml CVE-2024-4460Medium4.3fixed in 0.57.1 | Medium4.3 | 0.57.1 |
| Jun 82024 | zenml-io/zenml does not expire the session after password reset CVE-2024-4680Low3.9no fix yet | Low3.9 | No fix yet |
| Jun 62024 | Improper authorization in zenml CVE-2024-2035Medium6.5fixed in 0.56.2 | Medium6.5 | 0.56.2 |