Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108545— SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing

Quick assessment

Affected
SillyTavern SillyTavern
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SillyTavern 1.12.13 至 1.19.0 版本存在一个拒绝服务(DoS)漏洞,允许未经认证的远程攻击者通过耗尽系统资源来造成服务不可用。该漏洞的根本原因在于 body-parser 中间件在身份认证和访问白名单检查之前就已执行。攻击者可以发送体积庞大(最大达 500 MB)或经过压缩的 JSON 或 urlencoded 格式的请求体,并可并发发送,从而耗尽服务器的内存和 CPU 资源,导致服务拒绝。

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
SillyTavern SillyTavern 1.12.13≤ 1.19.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108545

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing
Source: CVE Program / CVE List V5
Vulnerability Description
SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authentication and whitelist checks. Attackers can send large or compressed JSON or urlencoded bodies up to 500 MB, optionally in parallel, to exhaust memory and CPU and deny service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SillyTavern SillyTavern 1.12.13 ~ 1.19.0 -

II. Public POCs for CVE-2026-108545

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108545

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-108545 (1)

Vendor Advisories for CVE-2026-108545 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108545

No comments yet


Leave a comment