Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 20, 2026 (about 3 months ago).

people · May 20, 2026

CVE-2026-42208 Pre-Authentication SQL Injection Hits LiteLLM Proxy

Share the canonical public link.

Share as image

Bishop Fox researchers confirmed CVE-2026-42208 a critical pre-authentication SQL injection in BerriAI LiteLLM proxy versions 1.81.16 through 1.83.6 on May 6 2026. An unauthenticated attacker could exploit a missing parameter binding in _enrich_failure_metadata_with_key_info by sending a crafted Authorization header to extract database data including virtual keys and credentials. Exploitation occurred in the wild within 36 hours of the April 25 2026 GitHub advisory with the fix released in version 1.83.7 on April 18 2026. Sysdig telemetry recorded the first observed exploitation 36 hours after disclosure according to Bishop Fox analysis.

Below validation threshold — auto-passed without scoring

Supporting evidence