HighVulnerabilityLLM-specific
GHSA-fh2c-86xm-pm2x: LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
- Identifiers
- CVE-2024-8984GHSA-fh2c-86xm-pm2x
- Published
- Record updated
- Affected
- litellm < 1.56.2
- Fixed in
- 1.56.2
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
A denial-of-service flaw affects berriai/litellm version v1.44.5. An unauthenticated attacker can append characters such as dashes (-) to the end of a multipart boundary in an HTTP request, and the server keeps processing each character. This consumes excessive resources and makes the service unavailable to all users, with no user interaction required.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database