Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 89.4%top 0.23%

CVE-2026-42208: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in BerriAI litellm

0
Critical
VulnerabilityCVE-2026-42208cvecve-2026-42208cwe-89
Published: 05/08/2026 (05/08/2026, 03:38:14 UTC)
Source: CVE Database V5
Vendor/Project: BerriAI
Product: litellm

Observed in the wild — via OffSeq Mirage

3
exposed hosts
First seen 06/29/2026 · last seen 07/01/2026 · activity in RU
View live telemetry on OffSeq Mirage

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
berriai/litellm
pkg:github/berriai/litellm
Affected versions
<1.83.7 >=1.81.16

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 19:18:37 UTC

Technical Analysis

LiteLLM, a proxy server for LLM APIs, versions >=1.81.16 and <1.83.7 contain an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements in SQL commands. Specifically, the database query used for API key validation concatenates the caller-supplied key directly into the query string instead of using parameterized queries. This flaw allows unauthenticated attackers to exploit the proxy's error-handling path by sending specially crafted Authorization headers to any LLM API endpoint, such as POST /chat/completions. Successful exploitation can lead to unauthorized reading and modification of the proxy's database, compromising access controls and credentials. The vulnerability is fixed in version 1.83.7. The CVSS 4.0 base score is 9.3 (critical), reflecting network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisory from Red Hat confirms the vulnerability and the patch availability.

Potential Impact

An unauthenticated attacker can exploit this SQL injection vulnerability to read and potentially modify the proxy's database. This can lead to unauthorized access to the proxy server and the credentials it manages, compromising the security of the system and any dependent services. The impact affects confidentiality, integrity, and availability of the proxy and its data.

Mitigation Recommendations

A patch is available in LiteLLM version 1.83.7 that fixes this SQL injection vulnerability by properly parameterizing the database queries. Users should upgrade affected installations to version 1.83.7 or later. There is no indication from the vendor advisory that any other mitigation or temporary workaround is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-04-25T05:04:37.027Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-42208","vendor":"Red Hat"}]

Threat ID: 69fd5dbdcbff5d86108b645b

Added to database: 05/08/2026, 03:51:25 UTC

Last enriched: 07/21/2026, 19:18:37 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 162

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses