mistralrs-server-core
Activity
- Latest release
- 5mo ago
- Total releases
- 5
- Cadence
- ~daily
- Last 12 months
- 5
Details
- License
- MIT
- First release
- Jan 27, 2026
| Version | Released | |
|---|---|---|
0.8.1
unknown
2 CVEs
GHSA-m3wp-48jr-vr4g
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Unbounded Remote Media Fetch and Video Frame Expansion DoSSummaryThe DetailsThree independent sinks contribute to the vulnerability: 1. Unbounded image/audio fetch (
2. Unbounded video fetch (
Identical pattern to the image path; the full video body is buffered into a 3. Unbounded FFmpeg frame extraction (
When
A 60 fps × 1080p × 180 s video therefore produces ~10 800 PNG files, consuming tens of gigabytes of disk space and saturating CPU. Entry point and auth The route is registered at PoCStep 1 – Create a long high-framerate video (requires FFmpeg on the attacker machine)
Step 2 – Serve the video (or an infinite byte stream) from an attacker-controlled HTTP server
Step 3 – Send the malicious request to the mistral.rs server
Expected observation For the video variant: For the image variant: server process RSS grows continuously until OOM kill (exit code 137) or memory is exhausted. Dynamic reproduction result (Phase 2) A Docker container running a verbatim reproduction of ImpactAny user of the mistral.rs OpenAI-compatible HTTP server is affected. Because the Reproduction artifacts
|
0.8.1
unknown
Dependencies (23)
+ 15 more |
|
0.8.0
unknown
2 CVEs
GHSA-m3wp-48jr-vr4g
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Unbounded Remote Media Fetch and Video Frame Expansion DoSSummaryThe DetailsThree independent sinks contribute to the vulnerability: 1. Unbounded image/audio fetch (
2. Unbounded video fetch (
Identical pattern to the image path; the full video body is buffered into a 3. Unbounded FFmpeg frame extraction (
When
A 60 fps × 1080p × 180 s video therefore produces ~10 800 PNG files, consuming tens of gigabytes of disk space and saturating CPU. Entry point and auth The route is registered at PoCStep 1 – Create a long high-framerate video (requires FFmpeg on the attacker machine)
Step 2 – Serve the video (or an infinite byte stream) from an attacker-controlled HTTP server
Step 3 – Send the malicious request to the mistral.rs server
Expected observation For the video variant: For the image variant: server process RSS grows continuously until OOM kill (exit code 137) or memory is exhausted. Dynamic reproduction result (Phase 2) A Docker container running a verbatim reproduction of ImpactAny user of the mistral.rs OpenAI-compatible HTTP server is affected. Because the Reproduction artifacts
|
0.8.0
unknown
Dependencies (23)
+ 15 more |
|
0.7.0
unknown
2 CVEs
GHSA-m3wp-48jr-vr4g
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Unbounded Remote Media Fetch and Video Frame Expansion DoSSummaryThe DetailsThree independent sinks contribute to the vulnerability: 1. Unbounded image/audio fetch (
2. Unbounded video fetch (
Identical pattern to the image path; the full video body is buffered into a 3. Unbounded FFmpeg frame extraction (
When
A 60 fps × 1080p × 180 s video therefore produces ~10 800 PNG files, consuming tens of gigabytes of disk space and saturating CPU. Entry point and auth The route is registered at PoCStep 1 – Create a long high-framerate video (requires FFmpeg on the attacker machine)
Step 2 – Serve the video (or an infinite byte stream) from an attacker-controlled HTTP server
Step 3 – Send the malicious request to the mistral.rs server
Expected observation For the video variant: For the image variant: server process RSS grows continuously until OOM kill (exit code 137) or memory is exhausted. Dynamic reproduction result (Phase 2) A Docker container running a verbatim reproduction of ImpactAny user of the mistral.rs OpenAI-compatible HTTP server is affected. Because the Reproduction artifacts
|
0.7.0
unknown
Dependencies (23)
+ 15 more |
|
0.7.0-alpha.4
unknown
2 CVEs
GHSA-m3wp-48jr-vr4g
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Unbounded Remote Media Fetch and Video Frame Expansion DoSSummaryThe DetailsThree independent sinks contribute to the vulnerability: 1. Unbounded image/audio fetch (
2. Unbounded video fetch (
Identical pattern to the image path; the full video body is buffered into a 3. Unbounded FFmpeg frame extraction (
When
A 60 fps × 1080p × 180 s video therefore produces ~10 800 PNG files, consuming tens of gigabytes of disk space and saturating CPU. Entry point and auth The route is registered at PoCStep 1 – Create a long high-framerate video (requires FFmpeg on the attacker machine)
Step 2 – Serve the video (or an infinite byte stream) from an attacker-controlled HTTP server
Step 3 – Send the malicious request to the mistral.rs server
Expected observation For the video variant: For the image variant: server process RSS grows continuously until OOM kill (exit code 137) or memory is exhausted. Dynamic reproduction result (Phase 2) A Docker container running a verbatim reproduction of ImpactAny user of the mistral.rs OpenAI-compatible HTTP server is affected. Because the Reproduction artifacts
|
0.7.0-alpha.4
unknown
Dependencies (23)
+ 15 more |
|
0.7.0-alpha.3
unknown
2 CVEs
GHSA-m3wp-48jr-vr4g
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Unbounded Remote Media Fetch and Video Frame Expansion DoSSummaryThe DetailsThree independent sinks contribute to the vulnerability: 1. Unbounded image/audio fetch (
2. Unbounded video fetch (
Identical pattern to the image path; the full video body is buffered into a 3. Unbounded FFmpeg frame extraction (
When
A 60 fps × 1080p × 180 s video therefore produces ~10 800 PNG files, consuming tens of gigabytes of disk space and saturating CPU. Entry point and auth The route is registered at PoCStep 1 – Create a long high-framerate video (requires FFmpeg on the attacker machine)
Step 2 – Serve the video (or an infinite byte stream) from an attacker-controlled HTTP server
Step 3 – Send the malicious request to the mistral.rs server
Expected observation For the video variant: For the image variant: server process RSS grows continuously until OOM kill (exit code 137) or memory is exhausted. Dynamic reproduction result (Phase 2) A Docker container running a verbatim reproduction of ImpactAny user of the mistral.rs OpenAI-compatible HTTP server is affected. Because the Reproduction artifacts
|
0.7.0-alpha.3
unknown
Dependencies (23)
+ 15 more |