Security Bypass in LiteLLM Proxy Server by BerriAI
CVE-2026-59823

5.3MEDIUM

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-59823?

LiteLLM, a proxy server for LLM APIs, previously lacked proper input validation for the user_config parameter, allowing authenticated users with a valid virtual key to bypass crucial security checks. This vulnerability enabled attackers to redirect server-side requests to unintended internal or external hosts, exposing sensitive endpoints that should have remained inaccessible. The issue has been addressed in version 1.83.9, which reinforces the importance of thorough input validation in API management.

Affected Version(s)

litellm < 1.83.9

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.