Skip to content
COOEY

FAIL › dossier

litellm

VENDOR

· dossier confidence 50%

LiteLLM is an AI Gateway proxy server for LLM APIs that suffered a severe security decline in 2026, with multiple critical and high-severity injection flaws (command, SQL, host-header) allowing arbitrary execution and unauthorized data access.

PROFILE
CategoryAI Gateway / LLM ProxyWhat they doLiteLLM is a proxy server that acts as an AI Gateway to call LLM APIs in OpenAI or native format.
SECURITY POSTURE

The security posture is critically compromised by a series of high and critical vulnerabilities in 2026, including command injection, SQL injection, and host-header parsing flaws that allow unauthorized access and arbitrary command execution.

Notable failures
  • CVE-2026-42271: Authenticated command injection allowing arbitrary host commands
  • CVE-2026-42208: SQL injection enabling unauthorized database access and credential theft
  • CVE-2026-49468: Host-header parsing flaw allowing host header manipulation
Patterns: Repeated critical and high-severity injection vulnerabilities (command, SQL, host-header) in the proxy server; Vulnerabilities persisting across multiple versions up to 1.59.8 before patching
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2026-06-08 CVE-2026-42271 high BerriAI LiteLLM allows authenticated users to execute arbitrary host commands via command injection.
2026-05-08 CVE-2026-42208 high BerriAI LiteLLM contains a SQL injection vulnerability enabling unauthorized database access and credential theft.
2026-06-22 CVE-2026-49468 critical LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effecti
2026-06-22 CVE-2026-49468 critical LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effecti
2026-06-21 CVE-2026-12773 high CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the
2026-06-21 CVE-2026-12773 high CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the
2026-05-08 CVE-2026-42208 critical CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
2026-05-08 CVE-2026-42208 critical CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
Open questions: Exact founding date and headquarters location of BerriAI · Current patch status and remediation timeline for CVE-2026-49468
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:50:07.415985+00:00