Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6607

21
FAUCET Score

OVERVIEW CVE-2026-6607 is a resource consumption vulnerability in lm-sys FastChat versions up to 0.2.36, specifically affecting the api_generate function in the Worker API Endpoint. This flaw enables remote attackers to exhaust system resources without requiring authentication or user interaction, potentially leading to denial of service conditions. SEVERITY The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network-based attack vector that requires no special privileges or user interaction. While the attack complexity is low and accessibility is straightforward for remote actors, the impact is limited to availability; no confidentiality or integrity compromise is possible. The EPSS score of 0.00017 indicates this vulnerability ranks lower than 99.95 percent of all CVEs in terms of real-world exploitation likelihood. EXPLOITATION STATUS The vulnerability has been publicly disclosed and patches are available, including commit c9e84b89c91d45191dc24466888de526fa04cf33. However, the initial patch in commit ff66426 was incomplete, as it addressed only the primary entry point while missing other vulnerable code paths. The vulnerability is listed on the Active Hot List and requires immediate patching to prevent potential resource exhaustion attacks, despite the currently low empirical exploitation rate.

Impacted Technologies

VendorProductVersion(s)CPE
Lm-SysFastchat
0.2.0, 0.2.1, 0.2.10, 0.2.11, 0.2.12, 0.2.13, 0.2.14, 0.2.15, 0.2.16, 0.2.17, 0.2.18, 0.2.19, 0.2.2, 0.2.20, 0.2.21, 0.2.22, 0.2.23, 0.2.24, 0.2.25, 0.2.26, 0.2.27, 0.2.28, 0.2.29, 0.2.3, 0.2.30, 0.2.31, 0.2.32, 0.2.33, 0.2.34, 0.2.35, 0.2.36, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.2.9CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 29th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-5h65-jx66-j7p5medium

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

Apr 20, 2026

References

gist.github.com / YLChen-007/87216a2d97a882d619e11dc67cd473b5
github.com / lm-sys/FastChat
github.com / lm-sys/FastChat/commit/c9e84b89c91d45191dc24466888de526fa04cf33
github.com / lm-sys/FastChat/issues/3833
github.com / lm-sys/FastChat/pull/3835
vuldb.com / submit/792227
vuldb.com / vuln/358242
vuldb.com / vuln/358242/cti