Intel

AIKIDO-2024-10196

litellm is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

25

Low Risk

This Affects:

pythonlitellm
1.0.0 - 1.42.4
Fixed in 1.42.5

TL;DR

Affected versions of the package allow allocation of resources without limits or throttling. Malicious users could exploit this by sending large request/response sizes, potentially overloading the server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

litellm is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.0.0 - 1.42.4.

How to fix this

Upgrade the litellm library to the patch version.