CVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

History

24 Jun 2026, 19:16

Type Values Removed Values Added
First Time Litellm
Litellm litellm
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/BerriAI/litellm/releases/tag/v1.84.0 - () https://github.com/BerriAI/litellm/releases/tag/v1.84.0 - Product, Release Notes
References () https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w - () https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w - Mitigation, Patch, Vendor Advisory
CPE cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

22 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 21:16

Updated : 2026-06-24 19:16


NVD link : CVE-2026-49468

Mitre link : CVE-2026-49468

CVE.ORG link : CVE-2026-49468


JSON object : View

Products Affected

litellm

  • litellm
CWE
CWE-290

Authentication Bypass by Spoofing