Skip to content
HighVulnerabilityLLM-specific

GHSA-fh2c-86xm-pm2x: LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

Published
Record updated
View JSON
Affected
  • litellm < 1.56.2
Fixed in
1.56.2
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

A denial-of-service flaw affects berriai/litellm version v1.44.5. An unauthenticated attacker can append characters such as dashes (-) to the end of a multipart boundary in an HTTP request, and the server keeps processing each character. This consumes excessive resources and makes the service unavailable to all users, with no user interaction required.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.