Executive brief
LiteLLM is a proxy server used to manage and unify access to various Artificial Intelligence (AI) models. A security flaw in how the software handles web requests could allow an unauthorized attacker to bypass security checks and access administrative management features. This could lead to full control over the AI gateway, potentially exposing sensitive API keys or disrupting AI services.
Technical details
An authentication bypass vulnerability exists in LiteLLM due to a Host-header parsing flaw in the `get_request_route()` function within `litellm/proxy/auth/auth_utils.py`. The authentication layer derives the effective route from `request.url.path`, which is reconstructed by the Starlette framework using the user-supplied Host header. By crafting a specific Host header, an attacker can cause the authentication gate to evaluate a different route than the one actually dispatched by FastAPI. This allows unauthenticated attackers to reach protected management endpoints. The vulnerability is mitigated if the proxy is deployed behind a WAF, CDN, or reverse proxy that validates or normalizes the Host header. The issue is fixed in version 1.84.0.
Affected products
- BerriAI litellm < 1.84.0
Timeline
- 2026-05-14: patched: Version 1.84.0 released
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-22: disclosed: CVE published to NVD