LiteLLMGHSA-gw2q-qw9j-rgv7
LiteLLM Vulnerable to Denial of Service (DoS)
High7.5CVE-2024-10188 · Published Mar 20, 2025 · updated Sep 10, 2026
A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | < 1.53.1.dev1 | 1.53.1.dev1 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2024-10188, PYSEC-2026-1549
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | LiteLLM Has a Leakage of Langfuse API Keys | High7.5 | No fix yet |
| Mar 202025 | LiteLLM Has an Improper Authorization Vulnerability | High8.1 | 1.61.15 |
| Mar 202025 | LiteLLM Reveals Portion of API Key via a Logging File | High7.5 | 1.44.12 |
| Mar 202025 | LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request | High7.5 | 1.56.2 |
| Mar 202025 | LiteLLM Vulnerable to Remote Code Execution (RCE) | High8.8 | No fix yet |
| Sep 132024 | LiteLLM Server-Side Request Forgery (SSRF) vulnerability | High7.5 | 1.44.8 |