PT-2026-33713 · Lmsys · Fastchat

·

CVE-2026-6607

·

Published

2026-04-20

·

Updated

2026-07-13

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions lm-sys fastchat versions prior to 0.2.37
Description A flaw in the Worker API Endpoint allows remote attackers to cause resource consumption through the manipulation of the api generate() function.
Recommendations Install the patch provided in commit c9e84b89c91d45191dc24466888de526fa04cf33. As a temporary workaround, restrict access to the api generate() function to minimize the risk of resource exhaustion.

Exploit

Fix

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6607
GHSA-5H65-JX66-J7P5
PYSEC-2026-2484

Affected Products

Fastchat