VulnSea

litellm has 38 CVEs on record between 2024 and 2026. Disclosures have slowed: 5 in the last 90 days after 19 in the 90 before. The busiest recent month was June 2026 with 10. The median CVSS is 7.5 (high), with 6 rated critical. 8% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 31 days (3 cases). The dominant weakness classes are CWE-287 (4) and CWE-266 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
8% vs 1% corpus
Median CVSS
7.5
Publish → KEV
31 d median(3)
Last 90 days
5 prev 19

Products

  • litellm 38
38
Total CVEs
6
Critical
3
CISA KEV
3
Exploited

litellm vulnerabilities

CVEs affecting litellm, newest first. Open any entry for full detail, references, and exploit status.

38 CVEsRSS

CVE-2026-37004Critical· 9.8
3w ago

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Midnightlitellm · litellmEPSS 0.55%via OSV
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

Abyssallitellm · litellmEPSS 0.87%via NVD
CVE-2026-59821High· 7.2
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by th…

Twilightlitellm · litellmEPSS 0.90%via NVD
CVE-2026-59820Medium· 6.5
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authen…

Sunlitlitellm · litellmEPSS 0.59%via NVD
CVE-2026-59819Medium· 4.9
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, a…

Sunlitlitellm · litellmEPSS 0.57%via NVD
CVE-2026-12799Medium· 4.3
3mo ago

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2026-12796Medium· 6.3
3mo ago

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

Sunlitlitellm · litellmEPSS 0.57%via OSV
CVE-2026-12798Medium· 6.3
3mo ago

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12797Medium· 6.3
3mo ago

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12795High· 7.3
3mo ago

LiteLLM: SSO Debug Flow Has Improper Authentication

LiteLLM: SSO Debug Flow Has Improper Authentication

Twilightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-12773High· 7.3
3mo ago

LiteLLM: MCP Proxy Has Improper Authentication

LiteLLM: MCP Proxy Has Improper Authentication

Twilightlitellm · litellmEPSS 1.0%via OSV
CVE-2026-12770Medium· 5.4
3mo ago

LiteLLM: Admin Key Handler Has Improper Authorization

LiteLLM: Admin Key Handler Has Improper Authorization

Sunlitlitellm · litellmEPSS 0.57%via OSV
CVE-2026-12772Medium· 6.3
3mo ago

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12771Medium· 5.0
3mo ago

LiteLLM: M2M JWT Handler Has Improper Authorization

LiteLLM: M2M JWT Handler Has Improper Authorization

Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

Abyssallitellm · litellmEPSS 0.82%via OSV
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

Midnightlitellm · litellmEPSS 0.65%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

Midnightlitellm · litellmEPSS 1.2%via NVD
CVE-2026-40217High· 8.8PoC
4mo ago

LiteLLM has a sandbox escape in custom-code guardrail

LiteLLM has a sandbox escape in custom-code guardrail

Midnightlitellm · litellmEPSS 15%via OSV
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

Abyssallitellm · litellmEPSS 84%via NVD
CVE-2026-42208Critical· 9.8CISA KEV0dayPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…

Hadallitellm · litellmEPSS 89%via NVD
CVE-2026-42203HighPoC
5mo ago

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

Midnightlitellm · litellmEPSS 0.37%via OSV
GHSA-69x8-hrgq-fjj8High
5mo ago

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

Twilightlitellm · litellmvia OSV
CVE-2026-35030Critical· 9.1PoC
5mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…

Abyssallitellm · litellmEPSS 0.63%via NVD
CVE-2026-35029HighPoC
5mo ago

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

Midnightlitellm · litellmEPSS 30%via OSV
CVE-2024-10188High· 7.5
1y ago

LiteLLM Vulnerable to Denial of Service (DoS)

LiteLLM Vulnerable to Denial of Service (DoS)

Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-9606High· 7.5
1y ago

LiteLLM Reveals Portion of API Key via a Logging File

LiteLLM Reveals Portion of API Key via a Logging File

Twilightlitellm · litellmEPSS 0.75%via OSV
CVE-2025-0628High· 8.1
1y ago

LiteLLM Has an Improper Authorization Vulnerability

LiteLLM Has an Improper Authorization Vulnerability

Twilightlitellm · litellmEPSS 0.34%via OSV
CVE-2024-8984High· 7.5
1y ago

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

Twilightlitellm · litellmEPSS 0.84%via OSV
CVE-2025-0330High· 7.5
1y ago

LiteLLM Has a Leakage of Langfuse API Keys

LiteLLM Has a Leakage of Langfuse API Keys

Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-6825High· 8.8
1y ago

LiteLLM Vulnerable to Remote Code Execution (RCE)

LiteLLM Vulnerable to Remote Code Execution (RCE)

Twilightlitellm · litellmEPSS 1.7%via OSV
litellm vulnerabilities (CVEs) · VulnSea