CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure
ID: 14d43843-9726-53bc-9f48-78db1c7daa21
STIX ID: report--14d43843-9726-53bc-9f48-78db1c7daa21
Feed Name: Security Affairs
A critical SQL injection (CVE-2026-42208) in LiteLLM versions 1.81.16–1.83.6 allowed unauthenticated attackers to inject crafted Authorization headers to reach a vulnerable database query, enabling schema enumeration and potential read/modify access to stored API keys, provider credentials, and environment configuration. The flaw was patched in 1.83.7 (April 19, 2026); Sysdig observed exploitation attempts approximately 36 hours after disclosure and published IOCs and a mitigation (set disable_error_logs:true) for users who cannot immediately upgrade.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
