ECHO-b229-8fda-451c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-b229-8fda-451c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-b229-8fda-451c
Upstream
Withdrawn
2026-05-03T07:30:04Z
Published
2026-05-05T18:23:31Z
Modified
2026-09-15T03:33:45Z
Summary
The vulnerable OIDC userinfo cache (token[:20] as cache key) was introduced in v1.80.8 via commit 4d13035. Our package is v1.78.0, which predates this feature entirely. The true affected range is >= 1.80.8, < 1.83.0. https://github.com/BerriAI/litellm/security/advisories/GHSA-jjhc-v7c2-5hh6 https://github.com/BerriAI/litellm/commit/4d13035bf9153efb34466336d63d1aa4489a6252
Details
References

Affected packages

Echo:PyPI / litellm

Package

Name
litellm
Purl
pkg:pypi/litellm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.78.0+echo.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-b229-8fda-451c.json"