CVE-2026-49468
Critical · CVSS 9.8LiteLLM — Authentication Bypass by Spoofing (CWE-290)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-290, CWE-290
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from request.url.path in litellm/proxy/auth/auth_utils.py::get_request_route(), which Starlette reconstructs from the Host header. A crafted Host could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. This vulnerability is fixed in 1.84.0.
Search profile — drives PoC discovery
Symbols litellmproxy_serverBerriAIGHSA-4xpc-pv4p-pm3wAI GatewayOpenAI format
Keywords CVE-2026-49468LiteLLM authentication bypassLiteLLM spoofingBerriAI litellm CWE-290LiteLLM proxy server auth bypassGHSA-4xpc-pv4p-pm3wLiteLLM 1.84.0 vulnerabilityLiteLLM PoC
Versions: < 1.84.0
Affected packages
| PyPI | litellm | 0 → 1.84.0 |
References
- https://github.com/BerriAI/litellm/releases/tag/v1.84.0
- https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w
- https://access.redhat.com/security/cve/CVE-2026-49468
- https://bugzilla.redhat.com/show_bug.cgi?id=2491520
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49468.json
Status: enriched · ingested 2026-06-25T00:00:38.000Z · profiled 2026-06-25T00:30:38.000Z