CVE-2026-12795
- EPSS 0.51%
- Veröffentlicht 21.06.2026 08:30:07
- Zuletzt bearbeitet 24.06.2026 20:15:08
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication...
CVE-2026-12774
- EPSS 0.26%
- Veröffentlicht 21.06.2026 03:45:06
- Zuletzt bearbeitet 24.06.2026 20:24:17
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Conne...
CVE-2026-12773
- EPSS 0.61%
- Veröffentlicht 21.06.2026 03:15:08
- Zuletzt bearbeitet 15.07.2026 02:18:11
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to ...
CVE-2026-12772
- EPSS 0.26%
- Veröffentlicht 21.06.2026 02:00:08
- Zuletzt bearbeitet 24.06.2026 20:28:58
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results ...
CVE-2026-12771
- EPSS 0.29%
- Veröffentlicht 21.06.2026 01:00:12
- Zuletzt bearbeitet 24.06.2026 20:31:58
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can b...
CVE-2026-12770
- EPSS 0.34%
- Veröffentlicht 21.06.2026 00:15:08
- Zuletzt bearbeitet 24.06.2026 20:37:26
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improp...
CVE-2026-47102
- EPSS 0.65%
- Veröffentlicht 21.05.2026 20:34:37
- Zuletzt bearbeitet 23.07.2026 16:10:00
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reac...
CVE-2026-47101
- EPSS 0.74%
- Veröffentlicht 21.05.2026 20:33:30
- Zuletzt bearbeitet 23.07.2026 16:10:00
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within...
CVE-2026-42208
- EPSS 89.42%
- Veröffentlicht 08.05.2026 03:38:14
- Zuletzt bearbeitet 15.07.2026 02:21:28
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of ...
CVE-2026-42203
- EPSS 0.37%
- Veröffentlicht 08.05.2026 03:36:58
- Zuletzt bearbeitet 15.07.2026 02:21:26
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafte...