CVE-2026-42208

Published May 8, 2026

Last updated a month ago

Exploit knownCVSS critical 9.3
Cloud
Zero-day
SQL injection
Server
Database
LiteLLM
OpenAI

Overview

Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
Source
security-advisories@github.com
NVD status
Analyzed
Products
litellm

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
BerriAI LiteLLM SQL Injection Vulnerability
Exploit added on
May 8, 2026
Exploit action due
May 11, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

security-advisories@github.com
CWE-89

Social media

Hype score
Not currently trending
  1. CVE-2026-42208 · v1.81.16 → 1.83.6 The API Gateway Blindspot: CVE-2026-42208 Exposes LiteLLM Deployments to Unauthenticated SQL Injection

    @lyrie_ai

    9 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 60% · CVE-2026-33626 · >=1.81.16 → >0.12.0 Two critical vulnerabilities in widely-deployed AI inference tooling — CVE-2026-33626 in LMDeploy (SSRF, CVSS 7.5) and CVE-2026-42208 in LiteLLM (SQL injection, CVSS 9.3) — were exploited in the wild within 12.5 and 36 hou

    @lyrie_ai

    1 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. LiteLLM shipped two CVEs in a quarter. CVE-2026-33634 — pre-auth SQL injection, CVSS 9.4. CVE-2026-42208 — RCE via crafted config, CVSS 9.3. For regulated AI deployments, that's a supply-chain conversation, not a patch conversation. https://t.co/DiNWjjsznQ

    @xSanjeevLabs

    28 May 2026

    55 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CRITICAL: CVE-2026-42208 - BerriAI LiteLLM SQL injection (CISA KEV). Attackers can read/modify proxy database & steal credentials. Patch by 2026-05-11. #CVE #PatchNow #ThreatIntel https://t.co/Iwl8nJhfXm

    @DFIR_Lab

    26 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 00:00 UTC: CVE-2026-42208 disclosed. CISA: CVE-2026-42208 added to Known Exploited Vulnerabilities — BerriAI LiteLLM Status: ✅ Confirmed exploited in the wild Date added: 2026-05-08 Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01…

    @lyrie_ai

    15 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-42208 · 1.81.16 → 1.83.7 CVE: CVE-2026-42208 CVSS: 0 (v3) — `` Severity: LOW Status: ✅ Confirmed exploited in the wild (CISA KEV)

    @lyrie_ai

    13 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations