Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3709 articles · 209723 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-59822KEVEXPLOITEDPATCHED
berriai · litellm

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

Affected Products

VendorProductVersions
berriailitellm< 1.84.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcelitellmcert_advisory90%

References

  • https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q(x_refsource_CONFIRM)
  • https://github.com/BerriAI/litellm/pull/26463(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/releases/tag/v1.84.0(x_refsource_MISC)

Related News (3 articles)

Tier D
SecurityWeek4h ago
Sangoma Switchvox Vulnerabilities Exploited in the Wild
→ No new info (linked only)
Tier B
BSI Advisories57d ago
[NEU] [hoch] LiteLLM: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB57d ago
CVE-2026-59822 | BerriAI litellm up to 1.83.x Streamable HTTP Endpoint UserAPIKeyAuth Authorization improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
litellm@1.84.0
CWECWE-287, CWE-306
PublishedJul 8, 2026
Last enriched57d agov2
Tags
sandbox escapecode injectionregex bypassbytecode manipulationmitigationauthenticated API
Trending Score128🔥
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-84377EXP
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Trending: 46
LOWCVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
LOWCVE-2026-59821EXPKEV
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
NONECVE-2026-12799EXP
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
NONECVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jul 8, 2026
Added to CISA KEV
Jul 8, 2026
Discovered by ZDM
Jul 8, 2026
Updated: vendor, product, affectedVersions, patchAvailable
Jul 8, 2026
Actively Exploited
Sep 3, 2026
Exploit Available
Sep 3, 2026
Patch Available
Sep 3, 2026

Version History

v2
Last enriched 57d ago
v2Tier C57d ago

Updated vendor to BerriAI, product to litellm, severity to CRITICAL, and affected versions to 1.83.x, with a new description detailing the vulnerability.

vendorproductaffectedVersionspatchAvailable
via VulDB
v157d ago

Initial creation