OpenAI’s ChatGPT Crawler Can Be Used to Trigger DDoS Attack on Websites, Researcher Claims

A security researcher found a vulnerability in ChatGPT's wrapper that could allow thousands of requests to be sent to a website, like a DDoS attack.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 21 January 2025 19:02 IST
Highlights
  • ChatGPT crawler can send thousands of network requests to a website
  • Researcher claimed the API does not deduplicate URLs to the same website
  • The vulnerability was given a high severity rating by the researcher

The researcher claimed to not have heard from OpenAI despite reporting the vulnerability multiple times

Photo Credit: Reuters

OpenAI's ChatGPT application programming interface (API) has a vulnerability that can be exploited to initiate a distributed denial of service (DDoS) attack on websites, according to details shared by a cybersecurity researcher. The chatbot can reportedly be used to send thousands of network requests to a website using the ChatGPT crawler. The researcher claims that the vulnerability, which was given a high severity rating, is still active with no response from the company on when the issue will be fixed.

ChatGPT API Allows Multiple Parallel Network Requests to Same Website

In a GitHub post shared earlier this month, Germany-based security researcher Benjamin Flesch detailed the vulnerability that exists within the ChatGPT API. The researcher also posted code for a proof of concept that sends 50 parallel HTTP requests to a test website, revealing how the bug can be used to trigger a DDoS attack.

Advertisement

According to the Flesch, the vulnerability surfaces when handling HTTP POST requests to https://chatgpt.com/backend-api/attributions. It is a method to send data to a server, typically used by the API endpoint to create new resources. While executing this function, the ChatGPT API requires a list of hyperlinks in the URL parameter.

In what appears to be a flaw in its API, OpenAI does not check whether a hyperlink to the same resource appears multiple times in the list, according to the researcher. Since hyperlinks to a website can be written in different ways, this results in the crawler sending multiple parallel network requests to the same website. Additionally, Flesch claims OpenAI does not enforce a limit on the maximum number of hyperlinks that can be added to the URL parameter and sent in a single request.

Advertisement

As a result, a malicious actor can potentially send thousands of hits to a website, which could quickly overwhelm its server. The security researcher gave this vulnerability a high severity “8.6 CVSS” rating since it is network-based, has low complexity in execution, and requires no privileges or user interaction but can cause a high impact on availability.

Flesch claimed to have reached out to both OpenAI and Microsoft (as its servers host the ChatGPT API) about the vulnerability multiple times via different channels after discovering the bug in January. He claimed that he reported it to the OpenAI security team, OpenAI employees via reports, the OpenAI data privacy officer, as well as Microsoft's security and Azure network operations team.

Advertisement

Despite making several attempts to flag the vulnerability, the researcher claimed that the issue is neither resolved nor has the AI firm acknowledged its existence. Gadgets 360 staff members were not able to verify the presence of the bug on the chatbot.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Unreal Engine 6 Comes With Claude, Gemini Models to Speed Up Game Development
  2. Carl Pei Tells Apple 'I'm Gonna Steal Your Customers' in Latest Video
  3. Xiaomi 17T Review
  4. iPhone 18 Pro Max Could Fit Existing iPhone 17 Pro Max Cases
  5. The OnePlus 15R Is Now Available in a New 16GB RAM Variant at This Price
  6. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order
  7. Bitcoin Slides as US Fed Warns Inflation Risks Could Keep Rates Elevated
  8. OnePlus N6 Confirmed to Launch in India With an 8,000mAh Battery
  9. Telecos Reportedly Oppose TRAI Proposal on Cheaper Voice and SMS Packs
  10. JBL Live 780NC, Live 680NC Debut in India With Up to 80-Hour Battery Life
  1. Amazon Prime Day 2026 Sale Dates Announced, Prime Membership Price Drops to Rs. 999
  2. Oppo Reno 15A 5G Launched With 7,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  3. Bitcoin Slips Below $64,000 as Hawkish US Fed Outlook Dampens Market Sentiment
  4. Epic Games Confirms Unreal Engine 6 Comes With Claude, Gemini Integration; Releases UE 5.8 Update
  5. OnePlus N6 Runs Geekbench With a MediaTek Dimensity 6 Series Chip, 6GB RAM
  6. JBL Live 780NC, JBL Live 680NC Launched in India With Up to 80-Hour Battery Life: Price, Features
  7. Samsung Health Update Starts Rolling Out With Vitals, Heart Health Score and More Improvements
  8. Nothing Founder Carl Pei Says He’s Coming for Apple’s Customers, One iPhone User at a Time
  9. Android 17 Offers Upgraded Android Switch Tool With Support for Transferring iMessages, Passkeys, Passwords and Alarms
  10. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order in Select Markets: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.