LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
ID: 6efdc329-33ba-552a-a263-7050d319ccfd
STIX ID: report--6efdc329-33ba-552a-a263-7050d319ccfd
Feed Name: securityonline.info
Threat Score
A critical (CVSS 9.5) vulnerability (CVE-2026-49468) in LiteLLM versions before 1.84.0 enables authentication bypass via Host header injection, potentially allowing unauthenticated access to management routes; administrators should upgrade to 1.84.0 or enforce strict upstream Host validation (CDN/WAF or reverse proxy) as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
