CVE-2026-42271
- EPSS 83.01%
- Veröffentlicht 08.05.2026 03:35:16
- Zuletzt bearbeitet 15.07.2026 02:21:30
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/...
CVE-2026-40217
- EPSS 6.5%
- Veröffentlicht 10.04.2026 13:43:23
- Zuletzt bearbeitet 15.07.2026 02:21:04
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
CVE-2026-35030
- EPSS 0.49%
- Veröffentlicht 06.04.2026 16:47:02
- Zuletzt bearbeitet 15.07.2026 02:20:40
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the s...
CVE-2026-35029
- EPSS 26.41%
- Veröffentlicht 06.04.2026 16:35:28
- Zuletzt bearbeitet 15.07.2026 02:20:40
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endp...
CVE-2026-33634
- EPSS 59.16%
- Veröffentlicht 23.03.2026 21:47:29
- Zuletzt bearbeitet 30.03.2026 18:50:38
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all ...
CVE-2025-11203
- EPSS 0.42%
- Veröffentlicht 29.10.2025 19:32:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to exploit this vulnerability. The...
CVE-2025-45809
- EPSS 0.25%
- Veröffentlicht 03.07.2025 00:00:00
- Zuletzt bearbeitet 12.03.2026 17:16:22
SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.
CVE-2024-6825
- EPSS 1.61%
- Veröffentlicht 20.03.2025 10:11:36
- Zuletzt bearbeitet 15.10.2025 13:15:49
BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the final '.' ...
CVE-2025-0330
- EPSS 0.55%
- Veröffentlicht 20.03.2025 10:09:34
- Zuletzt bearbeitet 01.08.2025 13:58:47
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_...
CVE-2024-9606
- EPSS 0.74%
- Veröffentlicht 20.03.2025 10:09:24
- Zuletzt bearbeitet 07.04.2025 14:50:05
In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire...