Patch released LiteLLM AI Gateway auth-bypass LiteLLM web-app
LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
CVE Tools coverage
LiteLLM’s authentication can be bypassed when a malicious actor injects a crafted HTTP Host header, potentially allowing unauthenticated access to protected management routes. The issue is tracked as CVE-2026-49468 (CVSS 9.5) affecting litellm (pip) versions earlier than < 1.84.0, making it critical for deployments that expose the proxy directly. Update to 1.84.0 to remediate; no confirmed exploitation was reported at the time of disclosure.