tag
Llm-Proxy
Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)·
LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs
patched
Critical
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468·
LiteLLM (BerriAI) proxy
patched
High
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102·
LiteLLM (LLM API proxy / gateway)
patched
Critical
LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29)·
LiteLLM (open-source LLM proxy/gateway), POST /guardrails/test_custom_code endpoint
patched