Fastchat
Vendor:
First CVE: Dec 30, 2024 · Active for 1 year
6
Total CVEs
More Total CVEs than 80% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fastchat over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2024
18 months ago
Most Recent CVE
Mar 20, 2025
494 days ago
CVE Severity & Scoring
Fastchat6 CVEs
17%
67%
17%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10044CRITICAL A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6 | Dec 30, 2024 | 9.3 | 26 | NO | NO |
CVE-2024-10908MEDIUM An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This | Mar 20, 2025 | 6.1 | 24 | NO | YES |
CVE-2024-10907HIGH In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed mul | Mar 20, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-10912HIGH A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper handling of form-data with a large | Mar 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-12376HIGH A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-11603HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validat | Mar 20, 2025 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Fastchat
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024-10-05 | 1 | 7.5 | 0.7% | 0 | 0 |
| 2024-09-23 | 1 | 9.3 | 0.5% | 0 | 0 |
| 0.2.36 | 4 | 7.2 | 0.7% | 0 | 1 |