[NEW] [high] LiteLLM: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in LiteLLM to disclose information, manipulate data, execute code, and bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities in LiteLLM can lead to information disclosure, data manipulation, code execution, and bypassing security measures.
- Who is affected
- Deployments of LiteLLM are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to the high severity and potential for exploitation.
- Action
- Update to the latest version of LiteLLM to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch LiteLLM
Get an email when a new LiteLLM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2263
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598190.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598200.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598210.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-59822Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 57% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59819 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59820 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59822 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerabilitycisa-kev
- lowGHSA-72m8-9m7m-h278: LiteLLM: Custom Code Guardrails production endpoints bypass code safety checksghsa
- highGHSA-7488-6r32-c95q: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallbackghsa
- lowGHSA-4g5m-c9r5-49xf: LiteLLM: Local file read via request-supplied OIDC file referencesghsa
- mediumGHSA-5jmr-gcrj-2c9q: LiteLLM: Arbitrary file write via path traversal in Skills archive extractionghsa
- highCVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to…nvd
- highCVE-2026-59821: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to…nvd
- mediumCVE-2026-59820: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to…nvd
- mediumCVE-2026-59819: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to…nvd
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11