Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
ID: 6154da58-136f-549a-b5e1-a46f40e7e7b6
STIX ID: report--6154da58-136f-549a-b5e1-a46f40e7e7b6
Feed Name: securityonline.info
Security researchers disclosed a critical pre-authentication SQL injection (CVE-2026-42208) in LiteLLM allowing unauthenticated attackers to run arbitrary SELECT queries against the backend PostgreSQL database; exploitation was observed in the wild within 36 hours of disclosure, with attackers targeting virtual API keys, stored provider credentials, and environment configuration. The advisory urges immediate patching to v1.83.7+, rotation of keys/credentials, placement behind reverse proxies to block malicious Authorization headers if unpatched, log audits for malformed Bearer tokens, and network isolation of LiteLLM instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
