litellm
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting litellm.
- CVE-2026-59819LiteLLM: Local file read via request-supplied OIDC file references4.9
- CVE-2026-59822LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback8.2
- CVE-2026-59820LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6.5
- CVE-2026-59821LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks7.2
- CVE-2026-49468LiteLLM: Authentication Bypass via Host Header Injection9.8
- CVE-2026-12799BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization4.3
- CVE-2026-12798BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery6.3
- CVE-2026-12797BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization6.3
- CVE-2026-12796BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration6.3
- CVE-2026-12795BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication7.3
- CVE-2026-12774BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery6.3
- CVE-2026-12773BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication7.3
- CVE-2026-12772BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration6.3
- CVE-2026-12771BerriAI litellm M2M JWT user_api_key_auth.py improper authorization5.0
- CVE-2026-12770BerriAI litellm Admin Key key_management_endpoints.py improper authorization5.4