PoC Archive PoC Archive

tag

Ai-Gateway

Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CVE-2026-56271webCRITICAL 9.8Patched2026-07-12LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030 web Patched
CVE-2026-35030webCRITICAL 9.1Patched2026-07-05LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
CVE-2026-35029webHIGH 8.8Patched2026-07-05Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
CVE-2026-42271webHIGH 8.7Patched2026-07-01