Skip to content
fastchatGHSA-5h65-jx66-j7p5

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

Medium5.3CVE-2026-6607 · Published Apr 20, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
fschat
PyPI
<= 0.2.26No fix yet
Details and references

A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API Endpoint. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is c9e84b89c91d45191dc24466888de526fa04cf33. It is suggested to install a patch to address this issue. Commit ff66426 patched this issue in api_generate of base_model_worker.py but missed other entry points.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
CVE-2026-6607, PYSEC-2026-2484

More fastchat advisories

All
DateAdvisory
Apr 20FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6608Medium5.3no fix yet
Mar 202025FastChat Server-Side Request Forgery vulnerability
CVE-2024-12376High7.5no fix yet
Mar 202025FastChat Server-Side Request Forgery vulnerability
CVE-2024-11603High7.5no fix yet
Mar 202025FastChat open redirect vulnerability
CVE-2024-10908Medium6.1no fix yet
Mar 202025FastChat Denial of Service vulnerability
CVE-2024-10912High7.5no fix yet
Mar 202025FastChat Uncontrolled Resource Consumption vulnerability
CVE-2024-10907High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.