CVE Tools

Berriai

23 CVEs tracked since 2024. Since Jun 2024, none of them reached CISA KEV.

Berriai CVEs per month

Jun 2024 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Berriai CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0660
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-0360
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06110

Products

The products that kept showing up in Berriai's monthly top three, with their CVEs summed over those months.

  1. Berriai/litellm122 months
  2. Litellm111 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Berriai.

  1. CVE-2026-89032BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer7.7
  2. CVE-2026-59823LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy—
  3. CVE-2026-84377LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters6.5
  4. CVE-2026-59819LiteLLM: Local file read via request-supplied OIDC file references4.9
  5. CVE-2026-59822LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback8.2
  6. CVE-2026-59820LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6.5
  7. CVE-2026-59821LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks7.2
  8. CVE-2026-49468LiteLLM: Authentication Bypass via Host Header Injection9.8
  9. CVE-2026-12799BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization4.3
  10. CVE-2026-12798BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery6.3
  11. CVE-2026-12797BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization6.3
  12. CVE-2026-12796BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration6.3
  13. CVE-2026-12795BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication7.3
  14. CVE-2026-12774BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery6.3
  15. CVE-2026-12773BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication7.3

The record

Peak rank
#109 in Jun 2024
Busiest month shown
Jun 2026, 11 CVEs
Months with a KEV entry
0 since Jun 2024
Monthly snapshots
3 since 2024
Berriai's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store