Vulnerability Description
A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sending multiple requests to the /auth/saml/callback endpoint, leading to uncontrolled memory consumption and eventual denial of service.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-0182?
CVE-2025-0182 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via ...
How severe is CVE-2025-0182?
CVE-2025-0182 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0182?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.