CVE-2026-49468
LiteLLM: Authentication Bypass via Host Header Injection
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from request.url.path in litellm/proxy/auth/auth_utils.py::get_request_route(), which Starlette reconstructs from the Host header. A crafted Host could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. This vulnerability is fixed in 1.84.0.
In plain language
AI Low urgencyCVE-2026-49468 is an authentication bypass bug in BerriAI litellm that was fixed in 1.84.0; typical small businesses using it should update now, but there’s no clear evidence it’s being exploited in the wild.
What to do
- Check what version of BerriAI litellm you are running and confirm whether you are on 1.84.0 or later.
- Upgrade to LiteLLM/BerriAI litellm 1.84.0 (or later) as soon as practical.
- Ask your IT person to verify the service is not exposed more broadly than needed (restrict access to trusted networks/users).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and Moreen·The Hacker News· Roundup Fortinet FortiGate Icarus
- LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)en-us·Daily CyberSecurity (securityonline.info)· Patch LiteLLM AI Gateway auth-bypass
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-49468 and every CVE in our database. Create a free account — no credit card required.
Create Free Account