VYPR
High severity7.5NVD Advisory· Published Oct 31, 2025· Updated Jun 17, 2026

CVE-2025-8849

CVE-2025-8849

Description

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the /api/memories endpoint. The key and value parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:librechat:librechat:0.7.9:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:librechat:librechat:0.7.9:-:*:*:*:*:*:*
    • (no CPE)range: <0.7.9
  • danny-avila/danny-avila/librechatv5
    Range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.