A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.

Project Subscriptions

Vendors Products
Lightningai Subscribe
Pytorch Lightning Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6922 A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.
Github GHSA Github GHSA GHSA-98fp-7v67-4v3q PyTorch Lightning denial of service vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-248

Fri, 01 Aug 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Lightningai
Lightningai pytorch Lightning
CPEs cpe:2.3:a:lightningai:pytorch_lightning:2.3.2:*:*:*:*:python:*:*
Vendors & Products Lightningai
Lightningai pytorch Lightning

Fri, 21 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.
Title Denial of Service in lightning-ai/pytorch-lightning
Weaknesses CWE-400
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:49:53.948Z

Reserved: 2024-08-20T17:13:44.574Z

Link: CVE-2024-8020

cve-icon Vulnrichment

Updated: 2025-03-20T17:53:52.008Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:39.137

Modified: 2025-10-15T13:15:53.443

Link: CVE-2024-8020

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-20T10:09:26Z

Links: CVE-2024-8020 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses