A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/berriai/litellm/commit/4f49f836aa844ac9b6bfbeff27e6f6b2b9cf3f61 | |
| https://huntr.com/bounties/554fc76b-3097-4223-b4cf-110b853e9355 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    15 Oct 2025, 13:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | |
| CWE | CWE-770 | 
15 Jul 2025, 14:59
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| Summary | 
 | |
| First Time | Litellm Litellm litellm | |
| CPE | cpe:2.3:a:litellm:litellm:1.65.4:dev2:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:nightly:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:dev6:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:1.65.4:dev8:*:*:*:*:*:* | |
| References | () https://huntr.com/bounties/554fc76b-3097-4223-b4cf-110b853e9355 - Exploit, Third Party Advisory | 
20 Mar 2025, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-20 10:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-8984
Mitre link : CVE-2024-8984
CVE.ORG link : CVE-2024-8984
JSON object : View
Products Affected
                litellm
- litellm
CWE
                