Skip to content
LiteLLMGHSA-gw2q-qw9j-rgv7

LiteLLM Vulnerable to Denial of Service (DoS)

High7.5CVE-2024-10188 · Published Mar 20, 2025 · updated Sep 10, 2026

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.53.1.dev11.53.1.dev1
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
CVE-2024-10188, PYSEC-2026-1549

More LiteLLM advisories

All LiteLLM
Advisory
LiteLLM Has a Leakage of Langfuse API Keys
High7.5Mar 20, 2025
LiteLLM Has an Improper Authorization Vulnerability
High8.1Mar 20, 2025
LiteLLM Reveals Portion of API Key via a Logging File
High7.5Mar 20, 2025
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High7.5Mar 20, 2025
LiteLLM Vulnerable to Remote Code Execution (RCE)
High8.8Mar 20, 2025
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High7.5Sep 13, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.