CVE-2026-59822

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-08 20:16

Updated : 2026-09-03 13:05


NVD link : CVE-2026-59822

Mitre link : CVE-2026-59822

CVE.ORG link : CVE-2026-59822


JSON object : View

Products Affected

litellm

  • litellm
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function