U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog
ID: 66f037b3-1b9e-5f4f-bb0d-a0449a404771
STIX ID: report--66f037b3-1b9e-5f4f-bb0d-a0449a404771
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-42208 — a critical (CVSS 9.3) SQL injection in BerriAI LiteLLM's proxy API key verification — to its Known Exploited Vulnerabilities catalog after researchers observed attackers exploiting the flaw roughly 36 hours after disclosure to enumerate database schemas and target high-value secrets; the vulnerability affects LiteLLM 1.81.16–1.83.6 and was fixed in 1.83.7, with mitigations and IoCs published and a federal remediation deadline of May 11, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
