logo

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

ID: 31104476-af95-5911-bd8a-da675a31dafa

STIX ID: report--31104476-af95-5911-bd8a-da675a31dafa

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Bill Toulas

...
...

A critical unauthenticated SQL injection (CVE-2026-42208) in the LiteLLM proxy enables attackers to exfiltrate API keys, provider credentials, and environment secrets by sending a crafted Authorization header to LLM API routes. A fix was issued in LiteLLM 1.83.7 (parameterized queries); researchers observed targeted exploitation beginning ~36 hours after public disclosure, and recommend upgrading, rotating exposed keys, or applying the suggested workaround (disable_error_logs:true) for unpatched instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.