BerriAI / Litellm
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93355 | LiteLLM Weak JWT Authentication via Email-Based User Lookup | HIGH | 7.6 | Sep 28, 2026 |
| CVE-2026-89032 | BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer | HIGH | 8.7 | Sep 25, 2026 |
| CVE-2026-59823 | LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-84377 | LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters | MEDIUM | 6.5 | Sep 2, 2026 |
| CVE-2026-59819 | LiteLLM: Local file read via request-supplied OIDC file references | LOW | 2.1 | Jul 8, 2026 |
| CVE-2026-59822 KEV | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | HIGH | 8.8 | Jul 8, 2026 |
| CVE-2026-59820 | LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | MEDIUM | 6.1 | Jul 8, 2026 |
| CVE-2026-59821 | LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks | LOW | 2.1 | Jul 8, 2026 |
| CVE-2026-49468 | LiteLLM: Authentication Bypass via Host Header Injection | CRITICAL | 9.5 | Jun 22, 2026 |
| CVE-2026-12799 | BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12798 | BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12797 | BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12796 | BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12795 | BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication | MEDIUM | 6.9 | Jun 21, 2026 |
| CVE-2026-12774 | BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12773 | BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication | MEDIUM | 6.9 | Jun 21, 2026 |
| CVE-2026-12772 | BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-12771 | BerriAI litellm M2M JWT user_api_key_auth.py improper authorization | LOW | 2.3 | Jun 21, 2026 |
| CVE-2026-12770 | BerriAI litellm Admin Key key_management_endpoints.py improper authorization | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-47102 | LiteLLM < 1.83.10 Privilege Escalation via User Update | HIGH | 8.7 | May 21, 2026 |
| CVE-2026-47101 | LiteLLM < 1.83.14 Privilege Escalation via API Key Generation | HIGH | 8.7 | May 21, 2026 |
| CVE-2026-42208 KEV | LiteLLM: SQL injection in Proxy API key verification | CRITICAL | 9.3 | May 8, 2026 |
| CVE-2026-42203 | LiteLLM: Server-Side Template Injection in /prompts/test endpoint | HIGH | 8.6 | May 8, 2026 |
| CVE-2026-42271 KEV | LiteLLM: Authenticated command execution via MCP stdio test endpoints | HIGH | 8.7 | May 8, 2026 |
| CVE-2026-40217 | LiteLLM: LiteLLM: Arbitrary Code Execution via bytecode rewriting | HIGH | 7.5 | Apr 10, 2026 |
Showing 1 to 25 of 35 CVEs