CVE Tools

Litellm

17 CVEs tracked since 2024. Since Jun 2024, none of them reached CISA KEV.

Litellm CVEs per month

Jun 2024 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Litellm CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0660
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06110

Products

The products that kept showing up in Litellm's monthly top three, with their CVEs summed over those months.

  1. Litellm172 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Litellm.

  1. CVE-2026-59819LiteLLM: Local file read via request-supplied OIDC file references4.9
  2. CVE-2026-59822LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback8.2
  3. CVE-2026-59820LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6.5
  4. CVE-2026-59821LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks7.2
  5. CVE-2026-49468LiteLLM: Authentication Bypass via Host Header Injection9.8
  6. CVE-2026-12799BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization4.3
  7. CVE-2026-12798BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery6.3
  8. CVE-2026-12797BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization6.3
  9. CVE-2026-12796BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration6.3
  10. CVE-2026-12795BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication7.3
  11. CVE-2026-12774BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery6.3
  12. CVE-2026-12773BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication7.3
  13. CVE-2026-12772BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration6.3
  14. CVE-2026-12771BerriAI litellm M2M JWT user_api_key_auth.py improper authorization5.0
  15. CVE-2026-12770BerriAI litellm Admin Key key_management_endpoints.py improper authorization5.4

The record

Peak rank
#115 in Jun 2024
Busiest month shown
Jun 2026, 11 CVEs
Months with a KEV entry
0 since Jun 2024
Monthly snapshots
2 since 2024
Litellm's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store