CVEs we hold for Berriai
Records whose assigning authority named Berriai as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-84377LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parametersBerriAI litellm
CVE-2026-59823LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM ProxyBerriAI litellm
CVE-2026-59821LiteLLM: Custom Code Guardrails production endpoints bypass code safety checksBerriAI litellm
CVE-2026-59820LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')BerriAI litellm
CVE-2026-35030LiteLLM has an authentication bypass via OIDC userinfo cache key collisionBerriAI litellm
CVE-2026-35029LiteLLM affected by privilege escalation via unrestricted proxy configuration endpointBerriAI litellm
CVE-2026-12799BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorizationBerriAI litellm
CVE-2026-12798BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgeryBerriAI litellm
CVE-2026-12797BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorizationBerriAI litellm
CVE-2026-12796BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expirationBerriAI litellm
CVE-2026-12795BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationBerriAI litellm
CVE-2026-12774BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgeryBerriAI litellm
CVE-2026-12773BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationBerriAI litellm
CVE-2026-12772BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expirationBerriAI litellm
CVE-2026-12770BerriAI litellm Admin Key key_management_endpoints.py improper authorizationBerriAI litellm
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.