Denial of Service Vulnerability in lm-sys FastChat by lm-sys
CVE-2026-6607
Key Information:
Badges
What is CVE-2026-6607?
A security issue has been identified in the lm-sys FastChat application, specifically affecting versions up to 0.2.36. This vulnerability is located in the api_generate function of the Worker API Endpoint, where improper handling can lead to excessive resource consumption. The attack can be executed remotely, and the exploit has already been made public. To mitigate the issue, a patch has been suggested, but while it addresses one method of exploitation in the base_model_worker.py file, other potential entry points may still remain unpatched. Users are encouraged to monitor updates from the vendor and apply available fixes to enhance their security posture.
Affected Version(s)
fastchat 0.2.0
fastchat 0.2.1
fastchat 0.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
