Skip to content

Critical - g4f zombie process leak #538

@EmminiX

Description

@EmminiX

🚨 DETAILED SECURITY INCIDENT REPORT

═══════════════════════════

📋 INCIDENT SUMMARY
• Type: Resource Exhaustion Attack (Software Bug)
• Duration: ~45 hours (Dec 11-13, 2025)
• Severity: CRITICAL - Near total system failure
• Root Cause: g4f library v0.3.2.9 zombie process leak

═══════════════════════════

📊 IMPACT ASSESSMENT
• System Load: 1 → 67 (6700% increase)
• CPU Usage: 99% sustained
• Zombie Processes: 216 accumulated
• Spawn Rate: ~1 zombie per minute
• Services Affected: ALL (VPS-wide)
• Downtime Risk: CRITICAL

═══════════════════════════

🔍 ROOT CAUSE ANALYSIS

The chatgpt-discord-bot used g4f (GPT4Free) library with Selenium to scrape free AI provider websites. The library spawned browser processes that NEVER terminated properly:

Process Tree:
python(3234) main.py
├─ python(5087)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions