PT-2026-33713 · Lmsys · Fastchat
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
lm-sys fastchat versions prior to 0.2.37
Description
A flaw in the Worker API Endpoint allows remote attackers to cause resource consumption through the manipulation of the
api generate() function.Recommendations
Install the patch provided in commit c9e84b89c91d45191dc24466888de526fa04cf33.
As a temporary workaround, restrict access to the
api generate() function to minimize the risk of resource exhaustion.Exploit
Fix
Improper Resource Release
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fastchat