FAIL › dossier
litellm
VENDOR· dossier confidence 50%
LiteLLM is an AI Gateway proxy server for LLM APIs that suffered a severe security decline in 2026, with multiple critical and high-severity injection flaws (command, SQL, host-header) allowing arbitrary execution and unauthorized data access.
PROFILE
CategoryAI Gateway / LLM ProxyWhat they doLiteLLM is a proxy server that acts as an AI Gateway to call LLM APIs in OpenAI or native format.
SECURITY POSTURE
The security posture is critically compromised by a series of high and critical vulnerabilities in 2026, including command injection, SQL injection, and host-header parsing flaws that allow unauthorized access and arbitrary command execution.
Notable failures
- CVE-2026-42271: Authenticated command injection allowing arbitrary host commands
- CVE-2026-42208: SQL injection enabling unauthorized database access and credential theft
- CVE-2026-49468: Host-header parsing flaw allowing host header manipulation
Patterns: Repeated critical and high-severity injection vulnerabilities (command, SQL, host-header) in the proxy server; Vulnerabilities persisting across multiple versions up to 1.59.8 before patching
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-08 | CVE-2026-42271 | high | BerriAI LiteLLM allows authenticated users to execute arbitrary host commands via command injection. |
| 2026-05-08 | CVE-2026-42208 | high | BerriAI LiteLLM contains a SQL injection vulnerability enabling unauthorized database access and credential theft. |
| 2026-06-22 | CVE-2026-49468 | critical | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effecti |
| 2026-06-22 | CVE-2026-49468 | critical | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effecti |
| 2026-06-21 | CVE-2026-12773 | high | CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the |
| 2026-06-21 | CVE-2026-12773 | high | CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the |
| 2026-05-08 | CVE-2026-42208 | critical | CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo |
| 2026-05-08 | CVE-2026-42208 | critical | CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo |
Open questions: Exact founding date and headquarters location of BerriAI · Current patch status and remediation timeline for CVE-2026-49468
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:50:07.415985+00:00