CVE•Published 2026-05-08•Modified 2026-07-15•4 articles on news•4 live references•NVD data

CVE-2026-42208Litellm · Litellm

Vulnerability data via NVD (ingested)

CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
100
Exploit Prediction Scoring System · top 0% of all CVEs
Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

Timeline
Published 2026-05-08
Modified 2026-07-15

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
★ 619·updated 2d ago
Agent-Threat-Rule/agent-threat-rulesTypeScript
Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. Executable, testable rules for prompt injection, tool poisoning, context exfiltration an…
★ 406·updated today
DarkFunct/TK-CVE-RepoPython
TK-CVE-Repo
★ 51·updated 3mo ago
1dayexploit/1day-archivePython
Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-…
★ 30·updated 1w ago
GODofExploit/exploit-arsenalPython
420 standalone Python-3 (stdlib-only) CVE exploits, each live-validated end-to-end against real vulnerable software with a write-up and a real-run screenshot. 102 in the CISA KEV c…
★ 15·updated 2w ago
holmanholdings/lionguardPython
Cathedral-Grade Security for AI Agents. Attack vectors updated daily. Local-first, zero API cost. MIT licensed.
★ 6·updated 1mo ago
ryansketch02-C3PO/intel-repositoryHTML
C3PO unified intelligence repository — threats, infrastructure, archives, and R&D
★ 3·updated 3w ago
siva010928/agnos-proxy-ossPython
Gateway-agnostic control plane for LLMs — an OpenAI-compatible governance proxy (auth, guardrails, budgets, routing, cost, observability) over a swappable engine: Bifrost / LiteLLM…
★ 3·updated 2d ago