LiteLLM: Authentication Bypass via Host Header Injection (CVE-2026-49468)
### Impact A Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from `request.url.path` in `litellm/proxy/auth/auth_utils.py::get_request_route()`, which Starlette reconstructs from the `Host` header. A crafted `Host` could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. **Most deployments are not affected.** The bypass is blocked by any upstream layer that validates or normalizes `Host`, such as: - a CDN or WAF, such as Cloudflare - a reverse proxy with `server_name` allowlists - a host-based load balancer **LiteLLM Cloud customers are not affected.** ### Patches Fixed in **`1.84.0`**. Upgrade to `1.84.0` or later. No configuration change is required. ### Workarounds If upgrading is not immediately possible, place the proxy behind an upstream component that validates or normalizes the `Host` header before forwarding (a CDN/WAF, a reverse proxy with explicit `server_name` allowlists, or a cloud load balancer with host-based routing rules), or otherwise restrict network access to the proxy listener. ### References - Patched release: [`v1.84.0`](https://github.com/BerriAI/litellm/releases/tag/v1.84.0) **Discovery Credit**: Le The Thang (KCSC) and Kim Ngoc Chung (One Mount Group)
AI Analysis
Technical Summary
LiteLLM is a proxy server that calls LLM APIs in OpenAI or native format. Before version 1.84.0, a Host-header parsing flaw in LiteLLM's proxy authentication mechanism could be exploited to bypass authentication. The authentication layer derives the effective route from request.url.path, which is reconstructed from the Host header by Starlette. An attacker can craft a Host header to manipulate the route evaluated by the auth gate, causing it to differ from the route dispatched by FastAPI. This discrepancy allows unauthenticated access to protected management routes. The issue is addressed and fixed in LiteLLM version 1.84.0.
Potential Impact
This vulnerability allows an unauthenticated attacker to bypass authentication controls and gain unauthorized access to protected management routes in the LiteLLM proxy server. Such access could lead to unauthorized management actions, potentially compromising the integrity and security of the system. The CVSS v4.0 base score is 9.5, indicating critical severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in LiteLLM version 1.84.0. Users should upgrade to version 1.84.0 or later to remediate this vulnerability. There is no indication of alternative mitigations or temporary fixes. Patch status is confirmed by the vendor advisory and the CVE description.
LiteLLM: Authentication Bypass via Host Header Injection (CVE-2026-49468)
Description
### Impact A Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from `request.url.path` in `litellm/proxy/auth/auth_utils.py::get_request_route()`, which Starlette reconstructs from the `Host` header. A crafted `Host` could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. **Most deployments are not affected.** The bypass is blocked by any upstream layer that validates or normalizes `Host`, such as: - a CDN or WAF, such as Cloudflare - a reverse proxy with `server_name` allowlists - a host-based load balancer **LiteLLM Cloud customers are not affected.** ### Patches Fixed in **`1.84.0`**. Upgrade to `1.84.0` or later. No configuration change is required. ### Workarounds If upgrading is not immediately possible, place the proxy behind an upstream component that validates or normalizes the `Host` header before forwarding (a CDN/WAF, a reverse proxy with explicit `server_name` allowlists, or a cloud load balancer with host-based routing rules), or otherwise restrict network access to the proxy listener. ### References - Patched release: [`v1.84.0`](https://github.com/BerriAI/litellm/releases/tag/v1.84.0) **Discovery Credit**: Le The Thang (KCSC) and Kim Ngoc Chung (One Mount Group)
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LiteLLM is a proxy server that calls LLM APIs in OpenAI or native format. Before version 1.84.0, a Host-header parsing flaw in LiteLLM's proxy authentication mechanism could be exploited to bypass authentication. The authentication layer derives the effective route from request.url.path, which is reconstructed from the Host header by Starlette. An attacker can craft a Host header to manipulate the route evaluated by the auth gate, causing it to differ from the route dispatched by FastAPI. This discrepancy allows unauthenticated access to protected management routes. The issue is addressed and fixed in LiteLLM version 1.84.0.
Potential Impact
This vulnerability allows an unauthenticated attacker to bypass authentication controls and gain unauthorized access to protected management routes in the LiteLLM proxy server. Such access could lead to unauthorized management actions, potentially compromising the integrity and security of the system. The CVSS v4.0 base score is 9.5, indicating critical severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in LiteLLM version 1.84.0. Users should upgrade to version 1.84.0 or later to remediate this vulnerability. There is no indication of alternative mitigations or temporary fixes. Patch status is confirmed by the vendor advisory and the CVE description.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_base
- Csaf Version
- 2.0
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik
- Advisory Id
- WID-SEC-W-2026-1975
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a32cff09f87a2db092d932f
Added to database: 06/17/2026, 16:48:48 UTC
Last enriched: 07/17/2026, 07:57:47 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 96
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.