CVE report
CVE-2024-6587high
LiteLLM - Server-Side Request Forgery
Events 90d
67
Distinct IPs
9
Severity
high
CISA KEV
Not listed
Detection signature
An event counts toward CVE-2024-6587 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /chat/completions
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 13 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2024-6587
- 209.222.101.19415 eventsUnited States· ReliableSite.Net LLC
- 185.150.191.23614 eventsUnited States· ReliableSite.Net LLC
- 104.248.117.7912 eventsUnited States· DigitalOcean, LLC
- 206.189.197.14310 eventsUnited States· DigitalOcean, LLC
- 5.61.209.2246 eventsSeychelles· Amarutu Technology Ltd
- 192.34.56.164 eventsUnited States· DigitalOcean, LLC
- 35.229.45.1003 eventsUnited States
- 104.243.41.282 eventsUnited States· ReliableSite.Net LLC
- 104.243.32.2351 eventsUnited States· ReliableSite.Net LLC
Top networks the attempts come from
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
Sample request paths observed
- /api/v1/chat/completions
- /v1/chat/completions