ChatGPT crawler flaw opens door to DDoS, prompt injection

ChatGPT crawler flaw opens door to DDoS, prompt injection

OpenAI’s ChatGPT crawler appears to be willing to initiate distributed denial of service (DDoS) attacks on arbitrary websites, a reported vulnerability the tech giant has yet to acknowledge.

In a write-up shared this month via Microsoft’s GitHub, Benjamin Flesch, a security researcher in Germany, explains how a single HTTP request to the ChatGPT API can be used to flood a targeted website with network requests from the ChatGPT crawler, specifically ChatGPT-User.

This flood of connections…

Article Source
https://www.theregister.com/2025/01/19/openais_chatgpt_crawler_vulnerability/

More From Author

Introducing queryable object metadata for Amazon S3 buckets (preview) | Amazon Web Services

Introducing queryable object metadata for Amazon S3 buckets (preview) | Amazon Web Services

Launch Free Tier EC2 Windows Instance – AWS

Launch Free Tier EC2 Windows Instance – AWS

Listen to the Podcast Overview

Watch the Keynote