CVE-2026-59822High· 8.2▾ Abyssal⚠ Exploited in the wildPoC availableLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 45.1 · likelihood 0.2 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Federal remediation due Sep 16, 2026
0.3% → 0.9%
1 GitHub repo
Added to the CISA catalog on Sep 2, 2026. Federal remediation due Sep 16, 2026. View catalog ↗
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
litellm < 1.84.0Upgrade past the affected range:
litellm 1.84.0Affected packages:
litellm < 1.84.0Patched in:
litellm 1.84.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12773High· 7.3LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-42271High· 8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-49468Critical· 9.8LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-42208Critical· 9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-12795High· 7.3LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-42203HighLiteLLM: Server-Side Template Injection in /prompts/test endpoint