Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 55%

LiteLLM: Authentication Bypass via Host Header Injection (CVE-2026-49468)

0
Critical
Published: 06/16/2026 (06/16/2026, 23:38:26 UTC)
Source: GCVE Database
Vendor/Project: BerriAI
Product: litellm

Description

### Impact A Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from `request.url.path` in `litellm/proxy/auth/auth_utils.py::get_request_route()`, which Starlette reconstructs from the `Host` header. A crafted `Host` could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. **Most deployments are not affected.** The bypass is blocked by any upstream layer that validates or normalizes `Host`, such as: - a CDN or WAF, such as Cloudflare - a reverse proxy with `server_name` allowlists - a host-based load balancer **LiteLLM Cloud customers are not affected.** ### Patches Fixed in **`1.84.0`**. Upgrade to `1.84.0` or later. No configuration change is required. ### Workarounds If upgrading is not immediately possible, place the proxy behind an upstream component that validates or normalizes the `Host` header before forwarding (a CDN/WAF, a reverse proxy with explicit `server_name` allowlists, or a cloud load balancer with host-based routing rules), or otherwise restrict network access to the proxy listener. ### References - Patched release: [`v1.84.0`](https://github.com/BerriAI/litellm/releases/tag/v1.84.0) **Discovery Credit**: Le The Thang (KCSC) and Kim Ngoc Chung (One Mount Group)

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected software

GitHub Actionsmore threats →ai
litellm/litellm
pkg:github/litellm/litellm
Affected versions
<=1.84.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/17/2026, 07:57:47 UTC

Technical Analysis

LiteLLM is a proxy server that calls LLM APIs in OpenAI or native format. Before version 1.84.0, a Host-header parsing flaw in LiteLLM's proxy authentication mechanism could be exploited to bypass authentication. The authentication layer derives the effective route from request.url.path, which is reconstructed from the Host header by Starlette. An attacker can craft a Host header to manipulate the route evaluated by the auth gate, causing it to differ from the route dispatched by FastAPI. This discrepancy allows unauthenticated access to protected management routes. The issue is addressed and fixed in LiteLLM version 1.84.0.

Potential Impact

This vulnerability allows an unauthenticated attacker to bypass authentication controls and gain unauthorized access to protected management routes in the LiteLLM proxy server. Such access could lead to unauthorized management actions, potentially compromising the integrity and security of the system. The CVSS v4.0 base score is 9.5, indicating critical severity with high impact on confidentiality, integrity, and availability.

Mitigation Recommendations

A fix is available in LiteLLM version 1.84.0. Users should upgrade to version 1.84.0 or later to remediate this vulnerability. There is no indication of alternative mitigations or temporary fixes. Patch status is confirmed by the vendor advisory and the CVE description.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_base
Csaf Version
2.0
Publisher
Bundesamt für Sicherheit in der Informationstechnik
Advisory Id
WID-SEC-W-2026-1975
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a32cff09f87a2db092d932f

Added to database: 06/17/2026, 16:48:48 UTC

Last enriched: 07/17/2026, 07:57:47 UTC

Last updated: 07/31/2026, 19:22:59 UTC

Views: 96

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses