LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
PatchLiteLLM AI GatewayOur summary
LiteLLM’s authentication can be bypassed when a malicious actor injects a crafted HTTP Host header, potentially allowing unauthenticated access to protected management routes. The issue is tracked as CVE-2026-49468 (CVSS 9.5) affecting litellm (pip) versions earlier than < 1.84.0, making it critical for deployments that expose the proxy directly. Update to 1.84.0 to remediate; no confirmed exploitation was reported at the time of disclosure.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.