Litellm is a lightweight language-model abstraction library that sits in the request path between applications and multiple LLM APIs, providing a unified interface for model routing and cost management across vendors such as OpenAI, Anthropic, and others. The vendor's vulnerability profile skews toward serious outcomes: a meaningful share reach critical severity, and the disclosures have an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability. The recurring exposure centers on the single Litellm product and clusters around input-handling and authorization weaknesses—notably SQL injection, code injection, and authorization bypass—that arise from the library's role parsing user inputs, dynamically handling API requests, and mediating access to backend LLM services. Given the library's position in production AI pipelines and its bridging function between untrusted application code and high-value model APIs, defenders should treat this vendor's advisories as high-priority and audit downstream applications that integrate it; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Litellm over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42208CRITICAL LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key chec | May 8, 2026 | 9.8 | 99 | YES | YES |
CVE-2026-42271HIGH LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server befo | May 8, 2026 | 8.8 | 98 | YES | YES |
CVE-2026-33634HIGH Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquas | Mar 23, 2026 | 8.8 | 93 | YES | NO |
CVE-2026-35029HIGH LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user | Apr 6, 2026 | 8.8 | 61 | NO | YES |
CVE-2024-6587HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making reques | Sep 13, 2024 | 7.5 | 53 | NO | YES |
CVE-2026-49468CRITICAL LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditi | Jun 22, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-12773CRITICAL A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mc | Jun 21, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-47101HIGH LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes f | May 21, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-59822HIGH LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to | Jul 8, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-47102HIGH LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, | May 21, 2026 | 8.8 | 37 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Litellm.
Media articles that mention a CVE ID that affects a product developed by Litellm — matched by CVE ID, not by vendor name.