Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242769
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048720
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229271
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4066
PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
4 days ago
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-4070
PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
4 days ago
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-4076
PyPI/litellm
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
4 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4069
PyPI/litellm
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
4 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4072
PyPI/litellm
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
4 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4074
PyPI/litellm
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
4 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4071
PyPI/litellm
LiteLLM: SSO Debug Flow Has Improper Authentication
4 days ago
No fix available
Severity - 5.5 (Medium)
PYSEC-2026-4067
PyPI/litellm
LiteLLM: MCP Proxy Has Improper Authentication
4 days ago
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-4075
PyPI/litellm
LiteLLM: M2M JWT Handler Has Improper Authorization
4 days ago
No fix available
Severity - 1.3 (Low)
PYSEC-2026-4073
PyPI/litellm
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
4 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4068
PyPI/litellm
LiteLLM: Admin Key Handler Has Improper Authorization
4 days ago
No fix available
Severity - 2.1 (Low)
GHSA-3cv6-jpf6-8222
PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
5 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-hx8v-g79f-8w5f
PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
17 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3861
PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
10 Sep
Fix available
Severity - 9.8 (Critical)
GHSA-6wvf-77m9-58rm
PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
27 Aug
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3478
PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
23 Jul
Fix available
Severity - 2.1 (Low)
Load more...
PyPI - OSV