PT-2026-93896 · Litellm · Litellm

CVE-2026-59823

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LiteLLM versions prior to 1.83.9
Description LiteLLM Proxy is susceptible to Server-Side Request Forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. An authenticated caller with a valid virtual key can bypass the is request body safe security check by placing the api base parameter inside the user config request body. While the system blocks top-level api base and base url parameters, it fails to inspect the user config object used to construct the outbound router. This allows the caller to redirect server-side requests to internal or external hosts, potentially exposing endpoints that should be inaccessible. Real-world incidents indicate this issue has been exploited in the wild.
Recommendations Update to version 1.83.9 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59823
ECHO-312D-3FE3-AE81
GHSA-HX8V-G79F-8W5F
PYSEC-2026-4070

Affected Products

Litellm