Description


SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authentication and whitelist checks. Attackers can send large or compressed JSON or urlencoded bodies up to 500 MB, optionally in parallel, to exhaust memory and CPU and deny service.

Related CPE's


Could not find any relations

Weaknesses



CWE-400

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

5.9 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-10T15:16:57.413Z

1 hour ago

Last modified

2026-10-10T15:16:57.530Z

1 hour ago