CVE-2025-8849EPSS p26.3%
CVE-2025-8849CVE-2025-8849
librechat / librechat
Description
LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.35% probability of exploitation · percentile 26.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |