CVE-2024-23826 - CVE House
Back to Database
Status published Medium CVE-2024-23826

Uploading an image with a specific filename causes a server-side DoS

Vulnerability Description

spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar image, an authenticated user may intentionally use a large Unicode filename which would lead to a server-side denial of service under Windows. This is due to no limitation of the length of the filename and the costly use of the Unicode normalization with the form NFKD on Windows OS. This vulnerability was fixed in the 2024.01.29 release.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23826

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

spbu_se_site
Vulnerable Versions:
< 2024.01.29

Timeline

Official Publish: January 29th, 2024
Last Modified: June 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

Weaknesses (CWE)