Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Litellm HIGH 8.2
CVE-2026-59822

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed…

Fix: 1.84.0+
Fix from $1,950 2026-07-08
Litellm HIGH 7.2
CVE-2026-59821

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails produc…

Fix: 1.82.0+
Fix from $1,950 2026-07-08
Litellm MEDIUM 6.5
CVE-2026-59820

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did n…

Fix: 1.83.7+
Fix from $1,600 2026-07-08
Litellm CRITICAL 9.8
CVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM prox…

Fix: 1.84.0+
Fix from $2,300 2026-06-22
Litellm MEDIUM 6.3
CVE-2026-12798

A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file li…

Fix: after 1.82.2
Fix from $1,600 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12797

A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_h…

Fix: after 1.82.5
Fix from $1,600 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12796

A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy…

Fix: after 1.82.2
Fix from $1,600 2026-06-21
Litellm HIGH 7.3
CVE-2026-12795

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/u…

Fix: after 1.82.2
Fix from $1,950 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12774

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client o…

Fix: after 1.82.2
Fix from $1,600 2026-06-21
Litellm CRITICAL 9.8
CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_s…

Fix: 1.59.9+
Fix from $2,300 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12772

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login…

Fix: 1.82.3+
Fix from $1,600 2026-06-21
Litellm HIGH 7.5
CVE-2026-12771

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py …

Fix: 1.82.3+
Fix from $1,950 2026-06-21
Litellm HIGH 8.8
CVE-2026-12770

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endp…

Fix: 1.63.2+
Fix from $1,950 2026-06-21
Litellm HIGH 8.8
CVE-2026-47101

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generat…

Fix: 1.83.14+
Fix from $1,950 2026-05-21
Litellm HIGH 8.8
CVE-2026-47102

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to u…

Fix: 1.83.10+
Fix from $1,950 2026-05-21
Litellm CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…

Fix: 1.83.7+
Fix from $2,300 2026-05-08
Litellm HIGH 8.8
CVE-2026-42203

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts…

Fix: 1.83.7+
Fix from $1,950 2026-05-08
Litellm HIGH 8.8
CVE-2026-40217EPSS 6%

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Fix: after 2026-04-08
Fix from $1,950 2026-04-10
Litellm CRITICAL 9.1
CVE-2026-35030

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt…

Fix: 1.83.0+
Fix from $2,300 2026-04-06
Litellm HIGH 8.8
CVE-2026-35029EPSS 26%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce a…

Fix: 1.83.0+
Fix from $1,950 2026-04-06
Litellm MEDIUM 5.4
CVE-2025-45809

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block"…

No fix yet
Fix from $1,600 2025-07-03
Litellm HIGH 7.5
CVE-2025-0330

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team setti…

No fix yet
Fix from $1,950 2025-03-20
Litellm HIGH 7.5
CVE-2024-9606

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key maskin…

Fix: 1.44.12+
Fix from $1,950 2025-03-20
Litellm HIGH 7.5
CVE-2024-8984

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such …

Fix: 1.65.4+
Fix from $1,950 2025-03-20
Litellm HIGH 8.8
CVE-2024-6825

BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules'…

Fix: 1.65.4+
Fix from $1,950 2025-03-20
Litellm HIGH 7.5
CVE-2024-6587EPSS 37%

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_bas…

Patch available
Fix from $1,950 2024-09-13
Litellm CRITICAL 9.8
CVE-2024-5751

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_de…

Mitigation only
Fix from $2,300 2024-06-27
Litellm MEDIUM 6.5
CVE-2024-5710

berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to…

No fix yet
Fix from $1,600 2024-06-27
Litellm HIGH 7.2
CVE-2024-5225

An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability ari…

Fix: after 1.40.2
Fix from $1,950 2024-06-06
Litellm HIGH 8.1
CVE-2024-4888

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` en…

Fix: 1.35.19+
Fix from $1,950 2024-06-06