[NEW] [medium] LiteLLM: Vulnerability enables information disclosure
A remote, authenticated attacker can exploit a vulnerability in LiteLLM to disclose information.
CSIRTS triage
- What
- An authenticated attacker can disclose sensitive information from LiteLLM.
- Who is affected
- LiteLLM deployments accessible to authenticated users.
- Urgency
- Medium priority; information disclosure may expose API keys, credentials, or model configuration details.
- Action
- Apply available security patches for LiteLLM and audit access logs for unauthorized data access.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch LiteLLM
Get an email when a new LiteLLM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3037
Recent advisories for LiteLLM
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] LiteLLM: Vulnerability Enables Bypass of Security Precautionscert-bund · 2026-09-03
- highexploited[NEW] [high] LiteLLM: Multiple vulnerabilitiescert-bund · 2026-09-03
- mediumCVE-2026-84377: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to…nvd · 2026-09-02
- criticalexploitedCVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerabilitycisa-kev · 2026-09-02
- criticalCVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows …nvd · 2026-08-27
- medium[NEW] [medium] LiteLLM: Vulnerability enables Security Bypasscert-bund · 2026-08-26
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03