CVE-2026-59822
EUVD-2026-4235908.07.2026, 20:16
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| litellm | litellm | 𝑥 < 1.84.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration