CVE-2026-42208

KEV
🔴 Łataj teraz

Wstrzyknięcie zapytania w LiteLLM umożliwia nieautoryzowany dostęp do bazy danych.

CVSS
9.8
EPSS
83.5%
Exploit
weaponized
Vendor
litellm
Opis źródłowy (NVD)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)83.5%
Opublikowano (NVD)2026-05-08 04:16:19 UTC
Ostatnia modyfikacja (NVD)2026-06-29 17:18:29 UTC
Referencje