Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-42208

99
FAUCET Score

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

First published: May 8, 2026Last modified: May 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.81.16, < 1.83.7CPE matchmatch criteria
cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
87.30%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · May 8, 2026
Metasploit: BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner · Apr 20, 2026
Nuclei: CVE-2026-42208 · May 30, 2026
This CVE's current EPSS score of 0.8730 is in the 99th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: litellmFixed in: 1.83.7
redhatworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-r75f-5x8p-qvmccritical

LiteLLM has SQL Injection in Proxy API key verification

Apr 24, 2026

References

access.redhat.com / security/cve/CVE-2026-42208
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
MitigationThird Party Advisory
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-42208.json
Third Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / BerriAI/litellm/releases/tag/v1.83.7-stable
ProductRelease Notes
github.com / BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc
MitigationPatchVendor Advisory