CVE-2026-42208: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in BerriAI litellm
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
AI Analysis
Technical Summary
LiteLLM, a proxy server for LLM APIs, versions >=1.81.16 and <1.83.7 contain an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements in SQL commands. Specifically, the database query used for API key validation concatenates the caller-supplied key directly into the query string instead of using parameterized queries. This flaw allows unauthenticated attackers to exploit the proxy's error-handling path by sending specially crafted Authorization headers to any LLM API endpoint, such as POST /chat/completions. Successful exploitation can lead to unauthorized reading and modification of the proxy's database, compromising access controls and credentials. The vulnerability is fixed in version 1.83.7. The CVSS 4.0 base score is 9.3 (critical), reflecting network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisory from Red Hat confirms the vulnerability and the patch availability.
Potential Impact
An unauthenticated attacker can exploit this SQL injection vulnerability to read and potentially modify the proxy's database. This can lead to unauthorized access to the proxy server and the credentials it manages, compromising the security of the system and any dependent services. The impact affects confidentiality, integrity, and availability of the proxy and its data.
Mitigation Recommendations
A patch is available in LiteLLM version 1.83.7 that fixes this SQL injection vulnerability by properly parameterizing the database queries. Users should upgrade affected installations to version 1.83.7 or later. There is no indication from the vendor advisory that any other mitigation or temporary workaround is required.
CVE-2026-42208: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in BerriAI litellm
Observed in the wild — via OffSeq Mirage
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
CVSS v4.0
Score 9.3critical
Affected software
pkg:github/berriai/litellmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LiteLLM, a proxy server for LLM APIs, versions >=1.81.16 and <1.83.7 contain an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements in SQL commands. Specifically, the database query used for API key validation concatenates the caller-supplied key directly into the query string instead of using parameterized queries. This flaw allows unauthenticated attackers to exploit the proxy's error-handling path by sending specially crafted Authorization headers to any LLM API endpoint, such as POST /chat/completions. Successful exploitation can lead to unauthorized reading and modification of the proxy's database, compromising access controls and credentials. The vulnerability is fixed in version 1.83.7. The CVSS 4.0 base score is 9.3 (critical), reflecting network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisory from Red Hat confirms the vulnerability and the patch availability.
Potential Impact
An unauthenticated attacker can exploit this SQL injection vulnerability to read and potentially modify the proxy's database. This can lead to unauthorized access to the proxy server and the credentials it manages, compromising the security of the system and any dependent services. The impact affects confidentiality, integrity, and availability of the proxy and its data.
Mitigation Recommendations
A patch is available in LiteLLM version 1.83.7 that fixes this SQL injection vulnerability by properly parameterizing the database queries. Users should upgrade affected installations to version 1.83.7 or later. There is no indication from the vendor advisory that any other mitigation or temporary workaround is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-25T05:04:37.027Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-42208","vendor":"Red Hat"}]
Threat ID: 69fd5dbdcbff5d86108b645b
Added to database: 05/08/2026, 03:51:25 UTC
Last enriched: 07/21/2026, 19:18:37 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 162
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.