Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh2c-86xm-pm2x

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.

Пакеты

Наименование

litellm

pip
Затронутые версииВерсия исправления

< 1.56.2

1.56.2

EPSS

Процентиль: 42%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.

EPSS

Процентиль: 42%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770