OVERVIEW CVE-2026-6607 is a resource consumption vulnerability in lm-sys FastChat versions up to 0.2.36, specifically affecting the api_generate function in the Worker API Endpoint. This flaw enables remote attackers to exhaust system resources without requiring authentication or user interaction, potentially leading to denial of service conditions. SEVERITY The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network-based attack vector that requires no special privileges or user interaction. While the attack complexity is low and accessibility is straightforward for remote actors, the impact is limited to availability; no confidentiality or integrity compromise is possible. The EPSS score of 0.00017 indicates this vulnerability ranks lower than 99.95 percent of all CVEs in terms of real-world exploitation likelihood. EXPLOITATION STATUS The vulnerability has been publicly disclosed and patches are available, including commit c9e84b89c91d45191dc24466888de526fa04cf33. However, the initial patch in commit ff66426 was incomplete, as it addressed only the primary entry point while missing other vulnerable code paths. The vulnerability is listed on the Active Hot List and requires immediate patching to prevent potential resource exhaustion attacks, despite the currently low empirical exploitation rate.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lm-Sys | Fastchat | 0.2.0, 0.2.1, 0.2.10, 0.2.11, 0.2.12, 0.2.13, 0.2.14, 0.2.15, 0.2.16, 0.2.17, 0.2.18, 0.2.19, 0.2.2, 0.2.20, 0.2.21, 0.2.22, 0.2.23, 0.2.24, 0.2.25, 0.2.26, 0.2.27, 0.2.28, 0.2.29, 0.2.3, 0.2.30, 0.2.31, 0.2.32, 0.2.33, 0.2.34, 0.2.35, 0.2.36, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.2.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.