litellm has 38 CVEs on record between 2024 and 2026. Disclosures have slowed: 5 in the last 90 days after 19 in the 90 before. The busiest recent month was June 2026 with 10. The median CVSS is 7.5 (high), with 6 rated critical. 8% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 31 days (3 cases). The dominant weakness classes are CWE-287 (4) and CWE-266 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 8% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- 31 d median(3)
- Last 90 days
- 5 prev 19
Worst active — by depth score
CVE-2026-42208Critical· 9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format80CVE-2026-42271High· 8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format76CVE-2026-59822High· 8.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format70CVE-2026-49468Critical· 9.8LiteLLM: Authentication Bypass via Host Header Injection66CVE-2024-5751Critical· 9.8BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution66
litellm vulnerabilities
CVEs affecting litellm, newest first. Open any entry for full detail, references, and exploit status.
38 CVEsRSS
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-5751Critical· 9.8PoCBerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…
CVE-2024-5710Medium· 5.3litellm vulnerable to improper access control in team management
litellm vulnerable to improper access control in team management
CVE-2024-5225Medium· 6.4SQL injection in litellm
SQL injection in litellm
CVE-2024-4890Medium· 4.9PoCSQL injection in litellm
SQL injection in litellm
CVE-2024-4888Medium· 6.5Arbitrary file deletion in litellm
Arbitrary file deletion in litellm
CVE-2024-4264High· 7.2litellm passes untrusted data to `eval` function without sanitization
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint