PT-2026-33713 · Lmsys · Fastchat

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6607

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions lm-sys fastchat versions prior to 0.2.37
Description A flaw in the Worker API Endpoint allows remote attackers to cause resource consumption through the manipulation of the api generate() function.
Recommendations Install the patch provided in commit c9e84b89c91d45191dc24466888de526fa04cf33. As a temporary workaround, restrict access to the api generate() function to minimize the risk of resource exhaustion.

Exploit

Fix

Resource Exhaustion

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-6607
GHSA-5H65-JX66-J7P5

Affected Products

Fastchat