CVE-2026-42208

Published May 8, 2026

Last updated 2 months ago

Exploit knownCVSS critical 9.3
Zero-day
SQL injection
API
Server
Cloud
LiteLLM
OpenAI
Database

Overview

Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
Source
security-advisories@github.com
NVD status
Analyzed
Products
litellm

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
BerriAI LiteLLM SQL Injection Vulnerability
Exploit added on
May 8, 2026
Exploit action due
May 11, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

security-advisories@github.com
CWE-89

Social media

Hype score
Not currently trending
  1. CVE-2026-42208 · <= 1.83.6 → < 1.83.7 CVE-2026-42208: The SQL Injection That Opens Your Entire AI Stack

    @lyrie_ai

    25 Jun 2026

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-42208: A pre-authentication SQL injection in LiteLLM CVE-2026-42208, CVSS 9.3 — the open-source AI gateway used by thousands of operators to centralize access to OpenAI, Anthropic, and AWS Bedrock — was exploited in the wild just 36 hours and 7 minutes after the…

    @lyrie_ai

    16 Jun 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2026-42208 · < 1.83.7 → >= 1.81.16 CVE-2026-42208 is a critical (CVSS 9.3) pre-authentication SQL injection in LiteLLM — the open-source LLM proxy used by thousands of engineering teams to centralize access to OpenAI, Anthropic, AWS Bedrock, and Azure OpenAI.

    @lyrie_ai

    16 Jun 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CVE-2026-42208 · v1.81.16 → 1.83.6 The API Gateway Blindspot: CVE-2026-42208 Exposes LiteLLM Deployments to Unauthenticated SQL Injection

    @lyrie_ai

    9 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 60% · CVE-2026-33626 · >=1.81.16 → >0.12.0 Two critical vulnerabilities in widely-deployed AI inference tooling — CVE-2026-33626 in LMDeploy (SSRF, CVSS 7.5) and CVE-2026-42208 in LiteLLM (SQL injection, CVSS 9.3) — were exploited in the wild within 12.5 and 36 hou

    @lyrie_ai

    1 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. LiteLLM shipped two CVEs in a quarter. CVE-2026-33634 — pre-auth SQL injection, CVSS 9.4. CVE-2026-42208 — RCE via crafted config, CVSS 9.3. For regulated AI deployments, that's a supply-chain conversation, not a patch conversation. https://t.co/DiNWjjsznQ

    @xSanjeevLabs

    28 May 2026

    55 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CRITICAL: CVE-2026-42208 - BerriAI LiteLLM SQL injection (CISA KEV). Attackers can read/modify proxy database & steal credentials. Patch by 2026-05-11. #CVE #PatchNow #ThreatIntel https://t.co/Iwl8nJhfXm

    @DFIR_Lab

    26 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 00:00 UTC: CVE-2026-42208 disclosed. CISA: CVE-2026-42208 added to Known Exploited Vulnerabilities — BerriAI LiteLLM Status: ✅ Confirmed exploited in the wild Date added: 2026-05-08 Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01…

    @lyrie_ai

    15 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CVE-2026-42208 · 1.81.16 → 1.83.7 CVE: CVE-2026-42208 CVSS: 0 (v3) — `` Severity: LOW Status: ✅ Confirmed exploited in the wild (CISA KEV)

    @lyrie_ai

    13 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations