Unauthenticated Access Vulnerability in LiteLLM Proxy Server by BerriAI
CVE-2026-59822
8.8HIGH
What is CVE-2026-59822?
LiteLLM, developed by BerriAI, is a proxy server that facilitates the usage of LLM APIs in OpenAI format. In versions prior to 1.84.0, a security flaw existed where an unauthenticated attacker could exploit a specially crafted Authorization header. This vulnerability enabled the attacker to bypass key validation, allowing unauthorized access to MCP tooling without a valid LiteLLM key. This issue was resolved in version 1.84.0, and users are encouraged to upgrade to this version to mitigate potential security risks.
Affected Version(s)
litellm < 1.84.0
