Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4066
  • PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4070
  • PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-4076
  • PyPI/litellm
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
PYSEC-2026-4069
  • PyPI/litellm
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
PYSEC-2026-4072
  • PyPI/litellm
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
PYSEC-2026-4074
  • PyPI/litellm
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
PYSEC-2026-4071
  • PyPI/litellm
LiteLLM: SSO Debug Flow Has Improper Authentication 2 days ago
  • No fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-4067
  • PyPI/litellm
LiteLLM: MCP Proxy Has Improper Authentication 2 days ago
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-4075
  • PyPI/litellm
LiteLLM: M2M JWT Handler Has Improper Authorization 2 days ago
  • No fix available
  • Severity - 1.3 (Low)
PYSEC-2026-4073
  • PyPI/litellm
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
PYSEC-2026-4068
  • PyPI/litellm
LiteLLM: Admin Key Handler Has Improper Authorization 2 days ago
  • No fix available
  • Severity - 2.1 (Low)
GHSA-3cv6-jpf6-8222
  • PyPI/litellm
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hx8v-g79f-8w5f
  • PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter 17 Sep
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3861
  • PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint 10 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-6wvf-77m9-58rm
  • PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint 27 Aug
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-3478
  • PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks 23 Jul
  • Fix available
  • Severity - 2.1 (Low)