logo

LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)

ID: 6efdc329-33ba-552a-a263-7050d319ccfd

STIX ID: report--6efdc329-33ba-552a-a263-7050d319ccfd

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

A critical (CVSS 9.5) vulnerability (CVE-2026-49468) in LiteLLM versions before 1.84.0 enables authentication bypass via Host header injection, potentially allowing unauthenticated access to management routes; administrators should upgrade to 1.84.0 or enforce strict upstream Host validation (CDN/WAF or reverse proxy) as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.