LiteLLM has an authentication bypass via OIDC userinfo cache key collision
48Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 9.4epss 0.5%
da publicação à arma43 dias
Publicada no NVD6 de abr.
1ª PoC+43d
probabilidade de exploração
0.5%top 60% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This configuration option is not enabled by default. Most instances are not affected. An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token. On cache hit, the attacker inherits the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled. Fixed in v1.83.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Produtos afetados
BerriAI · litellmPoCs públicas encontradas — 1
githubgithub.com/learner202649/CVE-2026-35030-PoC★ 0⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://access.redhat.com/errata/RHSA-2026:13545https://access.redhat.com/errata/RHSA-2026:28960https://access.redhat.com/errata/RHSA-2026:30056https://access.redhat.com/security/cve/CVE-2026-35030https://bugzilla.redhat.com/show_bug.cgi?id=2455509https://github.com/BerriAI/litellm/security/advisories/GHSA-jjhc-v7c2-5hh6https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35030.json