云虫漏洞库

CVE-2026-59822 - LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0. - 漏洞详情

漏洞编号:CVE-2026-59822

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-59822

CNNVD 编号:-

厂商/产品:litellm / litellm

影响范围:cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

CWE:CWE-287

发布/更新时间:2026-07-08 / 2026-08-28

漏洞描述

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

相关链接

相关漏洞

« 返回首页