CVE-2026-47102
- EPSS 0.38%
- Veröffentlicht 21.05.2026 20:34:37
- Zuletzt bearbeitet 11.06.2026 19:16:42
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reac...
CVE-2026-47101
- EPSS 0.48%
- Veröffentlicht 21.05.2026 20:33:30
- Zuletzt bearbeitet 11.06.2026 19:16:42
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within...
CVE-2026-42208
- EPSS 84.11%
- Veröffentlicht 08.05.2026 03:38:14
- Zuletzt bearbeitet 08.05.2026 19:19:34
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of ...
CVE-2026-42203
- EPSS 0.32%
- Veröffentlicht 08.05.2026 03:36:58
- Zuletzt bearbeitet 13.05.2026 17:14:58
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafte...
CVE-2026-42271
- EPSS 74.99%
- Veröffentlicht 08.05.2026 03:35:16
- Zuletzt bearbeitet 09.06.2026 01:22:09
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/...
CVE-2026-40217
- EPSS 0.72%
- Veröffentlicht 10.04.2026 13:43:23
- Zuletzt bearbeitet 27.04.2026 23:00:47
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
CVE-2026-35030
- EPSS 0.4%
- Veröffentlicht 06.04.2026 16:47:02
- Zuletzt bearbeitet 07.04.2026 20:20:56
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the s...
CVE-2026-35029
- EPSS 27.19%
- Veröffentlicht 06.04.2026 16:35:28
- Zuletzt bearbeitet 29.04.2026 20:16:30
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endp...
CVE-2026-33634
- EPSS 60.37%
- Veröffentlicht 23.03.2026 21:47:29
- Zuletzt bearbeitet 30.03.2026 18:50:38
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all ...
CVE-2025-11203
- EPSS 0.37%
- Veröffentlicht 29.10.2025 19:32:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to exploit this vulnerability. The...