OVERVIEW LiteLLM versions prior to 1.83.0 contain a critical authentication bypass vulnerability in the OIDC userinfo cache mechanism. When JWT authentication is enabled, the system uses only the first 20 characters of tokens as cache keys, allowing attackers to forge tokens that match legitimate users' cached credentials. This vulnerability only affects deployments with JWT/OIDC authentication explicitly enabled, which is not the default configuration, limiting the overall attack surface. SEVERITY The vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. An unauthenticated attacker can exploit this remotely by crafting malicious JWT tokens that match cached legitimate tokens, leading to identity spoofing and unauthorized access to user permissions and resources. The impact includes both high confidentiality and integrity compromise, though availability remains unaffected. EXPLOITATION STATUS There are currently no indicators of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) list, and community attention remains minimal with an EPSS score of 0.00113, indicating lower probability of exploitation relative to other CVEs. The issue has been remediated in version 1.83.0, and organizations running vulnerable versions should prioritize patching to address this critical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.83.0CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.