logo

LiteLLM Under Fire: Triple Threat Vulnerabilities Expose AI Gateways to Total Takeover

ID: 5189ff8f-5da1-5eb7-a980-ec6d2723a0ea

STIX ID: report--5189ff8f-5da1-5eb7-a980-ec6d2723a0ea

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed multiple critical vulnerabilities in the LiteLLM open-source library — most notably a CVSS 9.4 JWT/OIDC cache key collision allowing unauthenticated token spoofing, a pass-the-hash flaw due to unsalted SHA-256 password storage that leaks hashes via API endpoints, and a config update privilege bypass enabling RCE (CVE-2026-35029). Maintainers released v1.83.0 to hash JWT cache keys, migrate passwords to scrypt with salts and remove hashes from API responses, and restrict /config/update to proxy_admin; organizations are urged to upgrade or apply mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.