CodexGuild Knowledge Base
LiteLLM Vulnerable to Denial of Service (DoS)
Canonical as of Mar 20, 2025
LiteLLM Vulnerable to Denial of Service (DoS)
High severity. Affects litellm < 1.53.1.dev1. Upgrade to 1.53.1.dev1 or later.
CVE-2024-10188 / GHSA-gw2q-qw9j-rgv7 · severity: high · CVSS 7.5 · PyPI
Affected
litellm< 1.53.1.dev1 → fixed in 1.53.1.dev1
Details
A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.
Source: GHSA-gw2q-qw9j-rgv7 — GitHub Advisory Database (CC-BY-4.0).