Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3709 articles · 209712 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-84377EXPLOITED
berriai · litellm

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2.

Affected Products

VendorProductVersions
berriailitellm< 1.88.6, >= 1.89.0, < 1.96.2, main-latest (docker image ghcr.io/berriai/litellm:main-latest, repo digest ghcr.io/berriai/litellm@sha256:bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f)

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcelitellmcert_advisory90%

References

  • https://github.com/BerriAI/litellm/security/advisories/GHSA-3cv6-jpf6-8222(x_refsource_CONFIRM)
  • https://github.com/BerriAI/litellm/pull/36011(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/pull/36314(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/pull/36494(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/commit/473f72e63a9777d793fbbf57194d8ec4fb97bc1b(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/commit/820f247a6abba55cd87d130bef7bba7be3b29d37(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/commit/c898d341c02299cf2506d0d8e84cc67953043593(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/releases/tag/v1.88.6(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/releases/tag/v1.96.2(x_refsource_MISC)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [mittel] LiteLLM: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-84377 | BerriAI LiteLLM up to 1.88.5/1.96.1 Request Validation auth_utils.py server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-918, CWE-94
PublishedSep 2, 2026
Tags
sandbox escapecode injectionregex bypassbytecode manipulationmitigationauthenticated API
Trending Score46
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-59822EXPKEV
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Trending: 128
LOWCVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
LOWCVE-2026-59821EXPKEV
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
NONECVE-2026-12799EXP
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
NONECVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 2, 2026
Discovered by ZDM
Sep 2, 2026
Actively Exploited
Sep 3, 2026
Exploit Available
Sep 3, 2026