{"id":"CVE-2026-59822","title":"LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format","summary":"LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-287","CWE-306"],"vendor":"litellm","product":"litellm","affected":["litellm < 1.84.0"],"patched":["litellm 1.84.0"],"published":"2026-07-08","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59822","references":[{"url":"https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c","label":"security-advisories@github.com"},{"url":"https://github.com/BerriAI/litellm/pull/26463","label":"security-advisories@github.com"},{"url":"https://github.com/BerriAI/litellm/releases/tag/v1.84.0","label":"security-advisories@github.com"},{"url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59822"},{"url":"https://github.com/BerriAI/litellm"}],"tags":["nvd","kev","in-the-wild","exploit-available","osv","pip"],"epss":0.0087,"epssPercentile":0.56786,"ingestedAt":"2026-07-13T14:27:26.930Z","kev":true,"exploited":true,"kevDateAdded":"2026-09-02","kevDueDate":"2026-09-16","kevRansomware":false,"exploits":{"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2026-59822"],"checkedAt":"2026-09-21T15:29:50.676Z"},"exploitAvailable":true,"aliases":["GHSA-7488-6r32-c95q","PYSEC-2026-3479"],"ecosystem":"pip","slug":"CVE-2026-59822","body":"## Overview\n\nLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.\n\n## Affected\n\n- `litellm < 1.84.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `litellm 1.84.0`\n\n## Package advisory (CVE-2026-59822)\n\nAffected packages:\n\n- `litellm < 1.84.0`\n\nPatched in:\n\n- `litellm 1.84.0`\n\nSource: https://osv.dev/vulnerability/GHSA-7488-6r32-c95q","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":45.1,"likelihood":0.2,"exploitation":25,"ransomware":0},"changes":[{"seq":5384,"id":"CVE-2026-59822","ts":1788887275325,"field":"exploit_available","old":"false","new":"true"},{"seq":4267,"id":"CVE-2026-59822","ts":1788886389974,"field":"exploit_available","old":"true","new":"false"},{"seq":3017,"id":"CVE-2026-59822","ts":1788883053597,"field":"exploit_available","old":"false","new":"true"},{"seq":2046,"id":"CVE-2026-59822","ts":1788882457787,"field":"exploit_available","old":"true","new":"false"},{"seq":1120,"id":"CVE-2026-59822","ts":1788881894796,"field":"exploit_available","old":"false","new":"true"},{"seq":216,"id":"CVE-2026-59822","ts":1788383000078,"field":"exploited","old":"false","new":"true"},{"seq":215,"id":"CVE-2026-59822","ts":1788383000078,"field":"kev","old":"false","new":"true"}]}