Known Vulnerabilities for LiteLLM by BerriAI
Listed below are 10 of the newest known vulnerabilities associated with "LiteLLM" by "BerriAI".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-93355 json | LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-89032 json | BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows ... | Not Provided | 2026-09-25 | 2026-10-01 |
| CVE-2026-84377 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, an... | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-59823 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteL... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-59822 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamab... | Not Provided | 2026-07-08 | 2026-09-03 |
| CVE-2026-59821 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custo... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59820 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills ... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59819 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /hea... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-49468 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing ... | Not Provided | 2026-06-22 | 2026-07-15 |
| CVE-2026-47102 json | LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correc... | Not Provided | 2026-05-21 | 2026-07-15 |