Skip to content
LiteLLMGHSA-fh2c-86xm-pm2x

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

High7.5CVE-2024-8984 · Published Mar 20, 2025 · updated Sep 10, 2026

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.56.21.56.2
Details and references

More LiteLLM advisories

All LiteLLM
Advisory
LiteLLM Has a Leakage of Langfuse API Keys
High7.5Mar 20, 2025
LiteLLM Has an Improper Authorization Vulnerability
High8.1Mar 20, 2025
LiteLLM Reveals Portion of API Key via a Logging File
High7.5Mar 20, 2025
LiteLLM Vulnerable to Remote Code Execution (RCE)
High8.8Mar 20, 2025
LiteLLM Vulnerable to Denial of Service (DoS)
High7.5Mar 20, 2025
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High7.5Sep 13, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.