CVE-2024-8764: Lunary

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking the server from processing other requests.

Affected products

  • Lunary Lunary: before 1.4.23 (fixed in 1.4.23)

Published 2025-03-20. Last modified 2026-06-17.