LiteLLM: SQL injection in Proxy API key verification
100Vexday Risk Score
Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.
ssvc Actcvss 9.3epss 89%
da publicação à arma0 dias
Publicada no NVD8 de mai.
1ª PoC28 de abr.
metasploit20 de abr.
CISA KEV8 de mai.
probabilidade de exploração
89%top 1% das CVEs
exploração observada
simCISA + VulnCheck
9 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2026-05-11
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
BerriAI · litellmPoCs públicas encontradas — 9
githubgithub.com/HAERIN-L/poc_cve-2026-42208★ 0githubgithub.com/Zeltoc/threat-intel-brief-cve-2026-42208-litellm★ 0githubgithub.com/rootdirective-sec/CVE-2026-42208-Lab★ 0githubgithub.com/yendpoint/CVE-2026-42208-LAB★ 0githubgithub.com/ridhinva/litellm-sqli-scanner★ 0vulncheckvulncheck.com/xdb/0ab6c17887c6não verificadovulncheckvulncheck.com/xdb/9e4a1708ec20não verificadovulncheckvulncheck.com/xdb/efdf417c509fnão verificadovulncheckvulncheck.com/xdb/3eb42672ca96não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://access.redhat.com/security/cve/CVE-2026-42208https://bugzilla.redhat.com/show_bug.cgi?id=2463965https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stablehttps://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmchttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42208.jsonhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42208