BerriAI LiteLLM
8 known vulnerabilities in BerriAI LiteLLM, 2 critical, 4 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-59822 CVSS 8.8 high · actively exploited BerriAI LiteLLM Improper Authentication Vulnerability
- CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
- CVE-2026-33634 CVSS 9.4 critical · actively exploited Aquasecurity Trivy Embedded Malicious Code Vulnerability
Latest vulnerabilities
- CVE-2026-93355 CVSS 7.6 high LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to…
- CVE-2026-89032 CVSS 8.7 high BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated…
- CVE-2026-59823 CVSS 5.3 medium LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy…
- CVE-2026-84377 CVSS 6.5 medium LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any…
- CVE-2026-59822 CVSS 8.8 high · actively exploited BerriAI LiteLLM Improper Authentication Vulnerability
- CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
- CVE-2026-33634 CVSS 9.4 critical · actively exploited Aquasecurity Trivy Embedded Malicious Code Vulnerability