HIGH
Denial of Service in BerriAI/litellm
Published Mar 20, 2025
7.5
HIGHCVSS 3.0
EPSS 0.56%
Description
A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.
Affected products
-
Affected
- ≥ unspecified, < 1.53.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Berriai | Berriai/litellm | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7124 Advisory
- https://github.com/advisories/GHSA-gw2q-qw9j-rgv7 Advisory
- https://github.com/berriai/litellm/commit/21156ff5d0d84a7dd93f951ca033275c77e4f73c
- https://huntr.com/bounties/96a32812-213c-4819-ba4e-36143d35e95b
- https://nvd.nist.gov/vuln/detail/CVE-2024-10188
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Reserved Oct 18, 2024
Link CVE-2024-10188
CISA Vulnrichment
Updated Mar 20, 2025
Red Hat
No data
GitHub
Link GHSA-GW2Q-QW9J-RGV7