CVE-2024-11043
A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is sent in the board_name field during a PATCH request. By sending a large payload, the UI becomes unresponsive, rendering it impossible for users to interact with or manage the affected board. Additionally, the option to delete the board becomes inaccessible, amplifying the severity of the issue.
- Affected products
- Invokeai
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-400
- NVD status
- Deferred
- Published
- 2025-03-20
CVE-2024-11043 at NVD
No indexed exploits for CVE-2024-11043 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-11043 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.