Security
Loading…

CVE-2026-42208

CRITICALCVSS 9.8Known Exploited
Description

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Timeline
Published:May 8th, 2026 4:16 AM
Last modified:July 15th, 2026 2:21 AM
Added to KEV:May 8th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

litellm

Products

litellm
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute