Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2240774
AlmaLinux
5967
Alpaquita
16154
Alpine
4655
Android
3677
Azure Linux
17970
BellSoft Hardened Containers
769
Bitnami
9476
Chainguard
1048335
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68926
Echo
7835
GHC
3
GIT
108967
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148209
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25460
Red Hat
23525
Rocky Linux
4342
Root
19620
RubyGems
5327
SUSE
23442
SwiftURL
60
TuxCare
9897
Ubuntu
65983
VSCode
21
Wolfi
293784
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4066
PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
2 days ago
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-4070
PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
2 days ago
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-4076
PyPI/litellm
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
2 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4069
PyPI/litellm
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
2 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4072
PyPI/litellm
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
2 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4074
PyPI/litellm
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
2 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4071
PyPI/litellm
LiteLLM: SSO Debug Flow Has Improper Authentication
2 days ago
No fix available
Severity - 5.5 (Medium)
PYSEC-2026-4067
PyPI/litellm
LiteLLM: MCP Proxy Has Improper Authentication
2 days ago
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-4075
PyPI/litellm
LiteLLM: M2M JWT Handler Has Improper Authorization
2 days ago
No fix available
Severity - 1.3 (Low)
PYSEC-2026-4073
PyPI/litellm
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
2 days ago
No fix available
Severity - 2.1 (Low)
PYSEC-2026-4068
PyPI/litellm
LiteLLM: Admin Key Handler Has Improper Authorization
2 days ago
No fix available
Severity - 2.1 (Low)
GHSA-3cv6-jpf6-8222
PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
2 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-hx8v-g79f-8w5f
PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
17 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3861
PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
10 Sep
Fix available
Severity - 9.8 (Critical)
GHSA-6wvf-77m9-58rm
PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
27 Aug
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3478
PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
23 Jul
Fix available
Severity - 2.1 (Low)
Load more...
PyPI - OSV