Technology · Berriai
Berriai LiteLLM vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 31 vulnerabilities in Berriai LiteLLM: 1 in the last 7 days and 9 in the last 90 days, 7 of them critical and 3 exploited in the wild. The most recent, CVE-2026-89032, was published on 25 September 2026.
- Last 7 days
- 1
- Last 90 days
- 9
- Critical, all time
- 7
- Exploited in the wild
- 3
About Berriai LiteLLM
Python library that provides a unified interface for calling language models across multiple providers.
Latest Berriai LiteLLM vulnerabilities
- CVE-2026-89032: BerriAI LiteLLM tenant isolation bypass in semantic cachehighCVSS 7.7
- CVE-2026-59823: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated…mediumCVSS 4EPSS 0.4%
- CVE-2026-84377: LiteLLM proxy request parameter injection leading to credential exposuremediumCVSS 6.5EPSS 0.5%
- CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-30623: BerriAI LiteLLM remote code execution in MCP server creationinfoCVSS 8.8
- CVE-2026-59822: BerriAI LiteLLM authentication bypass in MCP endpointcriticalexploited in the wildCVSS 4EPSS 0.8%
- CVE-2026-59821: BerriAI LiteLLM code injection in Custom Code GuardrailsmediumCVSS 4EPSS 0.9%
- CVE-2026-59820: BerriAI LiteLLM path traversal in Skills archive extractionmediumCVSS 4EPSS 0.6%
- CVE-2026-59819: BerriAI LiteLLM local file read in health test_connection endpointmediumCVSS 4EPSS 0.6%
- CVE-2026-49468: BerriAI LiteLLM authentication bypass via Host header injectioncriticalCVSS 4EPSS 0.8%
- CVE-2026-12799: BerriAI LiteLLM improper authorization in ui_view_users functionmediumCVSS 4.3EPSS 0.4%
- CVE-2026-12798: BerriAI litellm SSRF in MCP OpenAPI Spec LoadermediumCVSS 6.3EPSS 0.4%
- CVE-2026-12797: BerriAI LiteLLM security bypass in BannedKeywords and AzureContentSafety hooksmediumCVSS 6.3EPSS 0.4%
- CVE-2026-12796: BerriAI LiteLLM insufficient session expiration in SSO flowmediumCVSS 6.3EPSS 0.6%
- CVE-2026-12795: BerriAI LiteLLM missing authentication in SSO debug endpointshighCVSS 7.3EPSS 0.8%
- CVE-2026-12774: BerriAI LiteLLM SSRF in MCP Server Connection TestingmediumCVSS 6.3
- CVE-2026-12773: BerriAI LiteLLM authentication bypass in MCP ProxyhighCVSS 7.3EPSS 1.0%
- CVE-2026-12772: BerriAI LiteLLM insufficient session expiration in Admin UI loginmediumCVSS 6.3EPSS 0.4%
- CVE-2026-12771: BerriAI LiteLLM improper authorization in M2M JWT HandlermediumCVSS 5EPSS 0.4%
- CVE-2026-12770: BerriAI LiteLLM improper authorization in key management endpointsmediumCVSS 5.4EPSS 0.6%
- CVE-2026-47102: BerriAI LiteLLM privilege escalation in user update endpointhighCVSS 8.8EPSS 0.8%
- CVE-2026-47101: BerriAI LiteLLM privilege escalation in API key generationhighCVSS 8.8EPSS 1.3%
- CVE-2026-42271: BerriAI LiteLLM OS command injection in MCP test endpointscriticalexploited in the wildCVSS 8.8EPSS 12.8%
- CVE-2026-42208: BerriAI LiteLLM SQL injection in Proxy API key verificationcriticalexploited in the wildCVSS 9.8EPSS 5.8%
- CVE-2026-42203: BerriAI LiteLLM code injection in /prompts/test endpointhighCVSS 8.8EPSS 0.7%
Most severe Berriai LiteLLM vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42208: BerriAI LiteLLM SQL injection in Proxy API key verificationcriticalexploited in the wildCVSS 9.8EPSS 5.8%
- CVE-2026-42271: BerriAI LiteLLM OS command injection in MCP test endpointscriticalexploited in the wildCVSS 8.8EPSS 12.8%
- CVE-2026-59822: BerriAI LiteLLM authentication bypass in MCP endpointcriticalexploited in the wildCVSS 4EPSS 0.8%
- CVE-2024-2952: BerriAI LiteLLM SSTI in completions endpointcriticalCVSS 9.8EPSS 1.3%
- CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-35030: BerriAI LiteLLM authentication bypass via OIDC cache key collisioncriticalCVSS 9.1EPSS 0.9%
- CVE-2026-49468: BerriAI LiteLLM authentication bypass via Host header injectioncriticalCVSS 4EPSS 0.8%
- CVE-2026-35029: BerriAI LiteLLM incorrect authorization in config update endpointhighCVSS 8.8EPSS 4.0%
- CVE-2026-40217: BerriAI LiteLLM remote code execution in guardrails componenthighCVSS 8.8EPSS 3.4%
- CVE-2026-47101: BerriAI LiteLLM privilege escalation in API key generationhighCVSS 8.8EPSS 1.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 1 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/litellm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Berriai LiteLLM vulnerabilities", https://junglewise.ai/threats/technologies/litellm, 26 September 2026.