PoC Archive PoC Archive

tag

Litellm

LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468 web Patched
CVE-2026-49468webCRITICAL 9.8Patched2026-07-05LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102 web Patched
CVE-2026-47102webHIGH 8.8Patched2026-07-05LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217) EPSS 15%
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29) web Patched
CVE-2026-40217webCRITICAL 8.8Patched2026-07-05LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030 web Patched
CVE-2026-35030webCRITICAL 9.1Patched2026-07-05LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
CVE-2026-35029webHIGH 8.8Patched2026-07-05Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
CVE-2026-42271webHIGH 8.7Patched2026-07-01