tag
Fastapi
Critical
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)·
Ormar (async Python ORM, commonly used with FastAPI/Starlette)
patched
Critical
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468·
LiteLLM (BerriAI) proxy
patched
High
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj)·
AutoGPT Platform (autogpt-platform-backend, chat/copilot feature)
unpatched