BerriAI LiteLLM

8 known vulnerabilities in BerriAI LiteLLM, 2 critical, 4 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-59822 CVSS 8.8 high · actively exploited BerriAI LiteLLM Improper Authentication Vulnerability
  • CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
  • CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
  • CVE-2026-33634 CVSS 9.4 critical · actively exploited Aquasecurity Trivy Embedded Malicious Code Vulnerability

Latest vulnerabilities

  • CVE-2026-93355 CVSS 7.6 high LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to…
  • CVE-2026-89032 CVSS 8.7 high BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated…
  • CVE-2026-59823 CVSS 5.3 medium LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy…
  • CVE-2026-84377 CVSS 6.5 medium LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any…
  • CVE-2026-59822 CVSS 8.8 high · actively exploited BerriAI LiteLLM Improper Authentication Vulnerability
  • CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
  • CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
  • CVE-2026-33634 CVSS 9.4 critical · actively exploited Aquasecurity Trivy Embedded Malicious Code Vulnerability