{"id":"CVE-2024-49363","summary":"Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskey","details":"Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a self-propagating reflected/amplified distributed denial-of-service via a maliciously crafted note. FileServerService.prototype.proxyHandler did not check incoming requests are not coming from another proxy server. An attacker can execute an amplified denial-of-service by sending a nested proxy request to the server and end the request with a malicious redirect back to another nested proxy request.\nLeading to unbounded recursion until the original request is timed out. This issue has been addressed in version 2024.11.0-alpha.3. Users are advised to upgrade. Users unable to upgrade may configure the reverse proxy to block requests to the proxy with an empty User-Agent header or one containing Misskey/. An attacker can not effectively modify the User-Agent header without making another request to the server.","aliases":["GHSA-gq5q-c77c-v236"],"modified":"2026-08-12T03:51:48.685935733Z","published":"2024-12-18T19:24:34.399Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49363.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-405","CWE-674"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49363.json"},{"type":"ADVISORY","url":"https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49363"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misskey-dev/misskey","events":[{"introduced":"e55a254353b608795386ae5efe1104f1177e6fd6"},{"last_affected":"e55a254353b608795386ae5efe1104f1177e6fd6"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"\u003c CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"},{"last_affected":"\u003c CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"}]}}],"versions":["\u003c CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H","3.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49363.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"}]}