CRITICAL

CVE-2026-42208

Litellm Litellm 2026-05-08 CVSS v3.1
CVSS
9.8
KEV

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

Summary dbcve.org

SQL injection vulnerability in LiteLLM proxy's API key validation logic. The database query mixes user-supplied Authorization header values directly into SQL query text instead of using parameterized queries. An unauthenticated attacker can exploit this through error-handling paths on LLM API routes to read/modify database data, including stored API credentials.

Mitigation

Upgrade LiteLLM to version 1.83.7 or later. Additionally, audit database access controls and rotate any credentials that may have been exposed, as the vulnerability allows reading credential data.

Patch Commit

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

89.42%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE