logo

Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild

ID: 6154da58-136f-549a-b5e1-a46f40e7e7b6

STIX ID: report--6154da58-136f-549a-b5e1-a46f40e7e7b6

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Security researchers disclosed a critical pre-authentication SQL injection (CVE-2026-42208) in LiteLLM allowing unauthenticated attackers to run arbitrary SELECT queries against the backend PostgreSQL database; exploitation was observed in the wild within 36 hours of disclosure, with attackers targeting virtual API keys, stored provider credentials, and environment configuration. The advisory urges immediate patching to v1.83.7+, rotation of keys/credentials, placement behind reverse proxies to block malicious Authorization headers if unpatched, log audits for malformed Bearer tokens, and network isolation of LiteLLM instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.