Sceawere
Vulnerability Detail
CVE-2026-108545UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SillyTavern Resource Exhaustion Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 3h ago
- Vendor
- SillyTavern
- Product
- SillyTavern
- Attack Type
- Uncontrolled Resource Consumption
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authentication and whitelist checks. Attackers can send large or compressed JSON or urlencoded bodies up to 500 MB, optionally in parallel, to exhaust memory and CPU and deny service.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-10T15:16:57.413Z",
"pubdate": "2026-10-10T15:16:57.413Z",
"executiveSummary": "SillyTavern versions 1.12.13 through 1.19.0 are susceptible to a Denial of Service (DoS) vulnerability originating from improper request body handling. The vulnerability exists because the body-parser middleware processes incoming requests prior to authentication or whitelist verification, allowing unauthenticated remote attackers to trigger resource exhaustion.\nBy submitting maliciously crafted JSON or urlencoded payloads—specifically those reaching the 500 MB limit—an attacker can induce significant CPU and memory pressure on the host environment. This flaw allows for parallel exploitation, which can rapidly lead to application crashes or complete service unavailability. Because the vulnerability is exploitable without authentication, the risk level is high for exposed instances, as it requires minimal technical sophistication to initiate a sustained resource depletion attack.",
"technicalDetails": "The vulnerability resides in the application's middleware orchestration. SillyTavern utilizes body-parser middleware to handle incoming HTTP requests before the request reaches the security layers responsible for authentication and access control (whitelist checks). This architectural ordering creates a logic flaw where the server commits memory and CPU cycles to parsing request payloads from unverified, unauthenticated sources.\nThe attack vector involves sending abnormally large or highly compressed JSON or urlencoded request bodies to the server's endpoints. The middleware is configured to accept payloads up to 500 MB. An attacker can leverage this by sending requests at the maximum allowed size. When the application receives these packets, the node environment attempts to buffer and parse the entire body into memory, resulting in rapid memory exhaustion. Because this process is synchronous in its initial parsing stage, the CPU usage spikes to handle the decompression and JSON transformation, effectively locking the main event loop.\nThe attack flow follows these steps: 1) The attacker identifies an exposed SillyTavern instance. 2) The attacker crafts an HTTP POST request with a Content-Length header or a payload size nearing the 500 MB threshold. 3) The server's body-parser middleware intercepts the request immediately upon arrival, bypassing the authentication modules. 4) The server allocates memory to hold the request body and initiates CPU-intensive parsing operations. 5) By initiating multiple parallel requests, the attacker compounds the memory overhead, eventually causing the Node.js process to crash due to heap out-of-memory (OOM) errors or stalling the server's ability to respond to legitimate users.\nThis vulnerability is present in versions 1.12.13 through 1.19.0. The impact is significant as it requires zero privileges, enabling anonymous remote attackers to degrade or crash the service. Since the parsing occurs before the application logic can evaluate the validity of the session or the IP address, standard application-level authentication is ineffective at preventing the initial request processing surge."
}