Knowledge base
CodexGuild Knowledge Base

LiteLLM Vulnerable to Denial of Service (DoS)

as of Mar 20, 2025 · applies to litellm < 1.53.1.dev1 · canonical · codexguild.com/kb/ghsa-gw2q-qw9j-rgv7 · exported 2026-10-11
Canonical as of Mar 20, 2025

LiteLLM Vulnerable to Denial of Service (DoS)

High severity. Affects litellm < 1.53.1.dev1. Upgrade to 1.53.1.dev1 or later.

CVE-2024-10188 / GHSA-gw2q-qw9j-rgv7 · severity: high · CVSS 7.5 · PyPI

Affected

  • litellm < 1.53.1.dev1 → fixed in 1.53.1.dev1

Details

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.

Source: GHSA-gw2q-qw9j-rgv7 — GitHub Advisory Database (CC-BY-4.0).