Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Litellm

First CVE: Apr 10, 2024Active for: 2 yearsTotal CVEs: 37
85.5
VTI Score
TOP TARGET

Litellm is a lightweight language-model abstraction library that sits in the request path between applications and multiple LLM APIs, providing a unified interface for model routing and cost management across vendors such as OpenAI, Anthropic, and others. The vendor's vulnerability profile skews toward serious outcomes: a meaningful share reach critical severity, and the disclosures have an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability. The recurring exposure centers on the single Litellm product and clusters around input-handling and authorization weaknesses—notably SQL injection, code injection, and authorization bypass—that arise from the library's role parsing user inputs, dynamically handling API requests, and mediating access to backend LLM services. Given the library's position in production AI pipelines and its bridging function between untrusted application code and high-value model APIs, defenders should treat this vendor's advisories as high-priority and audit downstream applications that integrate it; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
12.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
8.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Litellm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2024
2 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42208CRITICAL
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key chec
May 8, 20269.899YESYES
CVE-2026-42271HIGH
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server befo
May 8, 20268.898YESYES
CVE-2026-33634HIGH
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquas
Mar 23, 20268.893YESNO
CVE-2026-35029HIGH
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user
Apr 6, 20268.861NOYES
CVE-2024-6587HIGH
A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making reques
Sep 13, 20247.553NOYES
CVE-2026-49468CRITICAL
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditi
Jun 22, 20269.841NONO
CVE-2026-12773CRITICAL
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mc
Jun 21, 20269.840NONO
CVE-2026-47101HIGH
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes f
May 21, 20268.838NONO
CVE-2026-59822HIGH
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to
Jul 8, 20268.237NONO
CVE-2026-47102HIGH
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account,
May 21, 20268.837NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
30%
54%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None36 (97.3%)
Unknown0 (0.0%)
Required1 (2.7%)
Privileges Required
Low19 (51.4%)
High5 (13.5%)
None13 (35.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
3 CVEs
8.1% of CVEs· 100th percentile
Metasploit
1 CVE
2.7% of CVEs· 97th percentile
Nuclei
4 CVEs
10.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Litellm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Litellm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Litellm's Products

View all 5 CNAs →

Top CWEs