A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
|
Tue, 15 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litellm
Litellm litellm |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:dev2:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:dev6:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:dev8:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:nightly:*:*:*:*:*:* |
|
| Vendors & Products |
Litellm
Litellm litellm |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service. | |
| Title | Denial of Service (DoS) in berriai/litellm | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:19.131Z
Updated: 2025-10-15T12:49:58.738Z
Reserved: 2024-09-18T20:50:25.840Z
Link: CVE-2024-8984
Updated: 2025-03-20T17:54:07.171Z
Status : Modified
Published: 2025-03-20T10:15:45.583
Modified: 2025-10-15T13:15:56.553
Link: CVE-2024-8984
No data.