CVE-2026-59822
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
08/07/2026
Última modificación:
13/07/2026
Descripción
*** Pendiente de traducción *** LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Impacto
Puntuación base 4.0
8.80
Gravedad 4.0
ALTA
Puntuación base 3.x
8.20
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | 1.84.0 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



