{"data":{"id":"d397fe89-021c-4d79-a86c-731a25d939b9","title":"GHSA-fh2c-86xm-pm2x: LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request","summary":"A denial-of-service flaw affects berriai/litellm version v1.44.5. An unauthenticated attacker can append characters such as dashes (-) to the end of a multipart boundary in an HTTP request, and the server keeps processing each character. This consumes excessive resources and makes the service unavailable to all users, with no user interaction required.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fh2c-86xm-pm2x","publishedAt":"2025-03-20T12:32:49.000Z","cveId":"CVE-2024-8984","cweIds":["CWE-400","CWE-770"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.56.2 (fixed: 1.56.2)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0084,"epssCheckedAt":"2026-10-10T04:57:10.340Z","kevDateAdded":null,"advisoryAliases":["GHSA-fh2c-86xm-pm2x"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-03-20T12:32:49.000Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}