CVE-2026-42208Active Exploitation(litellm / litellm)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 53 mentions and remains active

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-11. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 168 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 240 mentions across 43 observed days

What's happening

  • Active exploitation reported across 168 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 55 signals
  • Technical details provided in 200 signals
  • Disclosure: 42 classified signals
  • General: 24 classified signals
  • Peaked 40d ago at 53 mentions (2026-04-29); latest day: 1
  • 240 total mentions across 43 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline240 mentions / 43d
013274053Mentions · 2026-04-27: 3Mentions · 2026-04-28: 16Mentions · 2026-04-29: 53Mentions · 2026-04-30: 21Mentions · 2026-05-01: 9Mentions · 2026-05-02: 3Mentions · 2026-05-03: 5Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-06: 9Mentions · 2026-05-07: 1Mentions · 2026-05-08: 9Mentions · 2026-05-09: 12Mentions · 2026-05-10: 9Mentions · 2026-05-11: 4Mentions · 2026-05-12: 4Mentions · 2026-05-13: 8Mentions · 2026-05-15: 4Mentions · 2026-05-16: 2Mentions · 2026-05-17: 1Mentions · 2026-05-19: 3Mentions · 2026-05-21: 1Mentions · 2026-05-22: 1Mentions · 2026-05-26: 2Mentions · 2026-05-27: 3Mentions · 2026-05-28: 4Mentions · 2026-05-29: 1Mentions · 2026-05-31: 2Mentions · 2026-06-01: 4Mentions · 2026-06-02: 5Mentions · 2026-06-05: 3Mentions · 2026-06-07: 1Mentions · 2026-06-09: 3Mentions · 2026-06-10: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 7Mentions · 2026-06-15: 2Mentions · 2026-06-16: 8Mentions · 2026-06-19: 2Mentions · 2026-06-22: 3Mentions · 2026-06-25: 5Mentions · 2026-06-26: 1Mentions · 2026-07-28: 1PoC Mentioned / Linked · 2026-04-28: 3PoC Mentioned / Linked · 2026-04-29: 4PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-04: 2PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-15: 2PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-06-02: 1PoC Mentioned / Linked · 2026-06-05: 2Exploit Tool / Code · 2026-04-28: 1Exploit Tool / Code · 2026-04-29: 1Exploit Tool / Code · 2026-05-04: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-05-19: 1Exploit Tool / Code · 2026-05-26: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 11Active Exploitation · 2026-04-29: 47Active Exploitation · 2026-04-30: 16Active Exploitation · 2026-05-01: 9Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-05-03: 5Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-06: 6Active Exploitation · 2026-05-08: 5Active Exploitation · 2026-05-09: 7Active Exploitation · 2026-05-10: 8Active Exploitation · 2026-05-11: 4Active Exploitation · 2026-05-12: 4Active Exploitation · 2026-05-13: 5Active Exploitation · 2026-05-15: 3Active Exploitation · 2026-05-16: 2Active Exploitation · 2026-05-17: 1Active Exploitation · 2026-05-19: 2Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-05-28: 2Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-06-01: 3Active Exploitation · 2026-06-02: 3Active Exploitation · 2026-06-05: 3Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-12: 3Active Exploitation · 2026-06-15: 2Active Exploitation · 2026-06-16: 3Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-06-25: 2Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-28: 8Patch / Workaround · 2026-04-29: 14Patch / Workaround · 2026-04-30: 4Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-06: 5Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-09: 3Patch / Workaround · 2026-05-10: 2Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-07-28: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 16Technical Details · 2026-04-29: 47Technical Details · 2026-04-30: 15Technical Details · 2026-05-01: 7Technical Details · 2026-05-02: 3Technical Details · 2026-05-03: 3Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 9Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 6Technical Details · 2026-05-09: 9Technical Details · 2026-05-10: 6Technical Details · 2026-05-11: 4Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 7Technical Details · 2026-05-15: 2Technical Details · 2026-05-17: 1Technical Details · 2026-05-19: 3Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 3Technical Details · 2026-05-28: 4Technical Details · 2026-05-31: 1Technical Details · 2026-06-01: 4Technical Details · 2026-06-02: 5Technical Details · 2026-06-05: 3Technical Details · 2026-06-07: 1Technical Details · 2026-06-09: 3Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 4Technical Details · 2026-06-15: 2Technical Details · 2026-06-16: 8Technical Details · 2026-06-22: 1Technical Details · 2026-06-25: 5Technical Details · 2026-06-26: 1Technical Details · 2026-07-28: 104-2705-0105-0505-0905-1305-1905-2706-0106-0906-1506-2507-28
Signal classification6 categories
Active Exploitation
15966.3%
Disclosure
4217.5%
General
2410.0%
Patch
114.6%
PoC
20.8%
Exploit
20.8%
Referenced assets113 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-273
Active Exploitation2Disclosure1
2026-04-2816
Active Exploitation10Disclosure4Patch2
2026-04-2953
Active Exploitation43Disclosure3General2Patch4PoC1
2026-04-3021
Active Exploitation15Disclosure4General1Patch1
2026-05-019
Active Exploitation9
2026-05-023
Active Exploitation1Disclosure1General1
2026-05-035
Active Exploitation5
2026-05-042
Disclosure1PoC1
2026-05-051
Active Exploitation1
2026-05-069
Active Exploitation6Disclosure3
2026-05-071
Disclosure1
2026-05-089
Active Exploitation5Disclosure2General1Patch1
2026-05-0912
Active Exploitation7Disclosure1General3Patch1
2026-05-109
Active Exploitation8General1
2026-05-114
Active Exploitation4
2026-05-124
Active Exploitation4
2026-05-138
Active Exploitation5Disclosure2General1
2026-05-154
Active Exploitation1Disclosure1Exploit1Patch1
2026-05-162
Active Exploitation2
2026-05-171
Active Exploitation1
2026-05-193
Active Exploitation2Disclosure1
2026-05-211
Active Exploitation1
2026-05-221
Active Exploitation1
2026-05-262
Disclosure1Exploit1
2026-05-273
Disclosure2General1
2026-05-284
Active Exploitation2Disclosure1General1
2026-05-291
Active Exploitation1
2026-05-312
General1Patch1
2026-06-014
Active Exploitation3Disclosure1
2026-06-025
Active Exploitation3Disclosure2
2026-06-053
Active Exploitation3
2026-06-071
Active Exploitation1
2026-06-093
Disclosure2General1
2026-06-101
General1
2026-06-111
Active Exploitation1
2026-06-127
Active Exploitation3Disclosure1General3
2026-06-152
Active Exploitation2
2026-06-168
Active Exploitation3Disclosure3General2
2026-06-192
Disclosure1General1
2026-06-223
Active Exploitation1Disclosure1General1
2026-06-255
Active Exploitation2Disclosure1General2
2026-06-261
Disclosure1
2026-07-281
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 LiteLLM CVE-2026-42208 exploited in ~36 hours. A pre-auth SQL injection exposed credential tables with LLM and cloud keys—turning a simple flaw into account-level risk. No PoC needed; advisory and schema were enough. 🔗 Read details → https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html

    Post summary

    LiteLLM CVE-2026-42208, a pre-auth SQL injection, has been actively exploited within about 36 hours, exposing credential tables and cloud keys. No PoC or patch is mentioned.

    44341294018.3K
    1.8M followersView on X
  • Hunter@HunterMapping
    Active Exploitation

    🚨Alert🚨 CVE-2026-42208: A Critical Pre-Auth SQL Injection in LiteLLM. 🧐Detail :https://www.sysdig.com/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure?utm_campaign=Oktopost-2026+Threat+Research&utm_content=Oktopost-linkedin&utm_medium=linkedin&utm_source=organic-social&utm_term=Cloud+Security%2CThreat+Detection%2CBlog%2COpen+Source%2CThreat+Research%2CSecurity+Teams 📊 112.8K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22litellm%22 👇Query HUNTER : http://product.name="litellm" 📰Refer:https://www.linkedin.com/posts/sysdig_new-from-sysdig-threat-research-cve-2026-activity-7454607076414222337-4QWW https://securityonline.info/litellm-sql-injection-exploited-in-the-wild-cve-2026-42208/ https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-a-critical-litellm-pre-auth-sqli-flaw/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post alerts that CVE-2026-42208, a critical pre‑authentication SQL injection in LiteLLM, has already been exploited in the wild, as evidenced by external reports and references.

    013040123.3K
    26.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added BerriAI LiteLLM SQL injection vulnerability CVE-2026-42208 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/G2fTbSPBb1

    Post summary

    CVE-2026-42208, an SQL injection flaw in BerriAI LiteLLM, is listed as actively exploited and noted in a Known Exploited Vulnerabilities Catalog, with a link for further details.

    61023355.5K
    299.5K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    📢 New from @Sysdig Threat Research: CVE-2026-42208 is a critical pre-auth SQL injection in LiteLLM, an open-source gateway for OpenAI, Anthropic, and more. It was a very targeted AI attack: • Direct access to API keys, provider creds, env configs • Clear schema awareness (Prisma casing) • Precise column enumeration • Infra rotation mid-attack AI gateways centralize high-value credentials, making them prime targets. Patch. Rotate. Lock down. Full article >>> https://okt.to/pb80hZ

    Post summary

    Sysdig’s Threat Research reports that LiteLLM is being actively exploited via a pre‑auth SQL injection, enabling attackers to retrieve high‑value credentials; patches and lock‑down measures are advised.

    2802192.7K
    10.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🟥 ثغره في LiteLLM CVE-2026-42208 درجه الخطورة CVSS 9.8 LiteLLM هو أداة (مكتبة بايثون و وكيل) مفتوحة المصدر، تعمل كبوابة موحدة للربط مع أكثر من 100 نموذج لغوي (LLMs) https://t.co/dg0ea6uXV1

    Post summary

    The tweet announces CVE-2026-42208 in LiteLLM with a high CVSS score but provides no details about exploitation, PoC, or mitigation.

    04016183.3K
    49.3K followersView on X
  • Audrey Renée Bentley@BentleyAudrey
    Disclosure

    https://api.cyfluencer.com/s/rce-in-litellm-cve-2026-42208-how-two-vulnerabilities-and-36-hours-turn-an-ai-gateway-into-a-backdoor-27224/1 RCE in LiteLLM (CVE-2026-42208): How Two Vulnerabilities and 36 Hours Turn an AI Gateway into a Backdoor

    Post summary

    The headline announces a CVE‑2026‑42208 Remote Code Execution vulnerability in LiteLLM, outlining two underlying issues, but it does not provide PoC code, exploit tools, or patch information.

    01016610.6K
    33.3K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-42208 (CVSS N/A): Pre-auth SQL injection in LiteLLM may expose sensitive backend data and API credentials. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJMaXRlTExNLUFQSSI%3D 🎯17.6K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="LiteLLM-API" 🔖Refer: https://securityonline.info/litellm-sql-injection-exploited-in-the-wild-cve-2026-42208/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑42208 is a pre‑authentication SQL injection vulnerability in LiteLLM that has been actively exploited in the wild, with no patch or workaround mentioned.

    0301351.5K
    14.4K followersView on X
  • Bishop Fox@bishopfox
    Active Exploitation

    A failed login should not take 6 seconds. Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data. Observed in the wild roughly 36 hours after disclosure. Upgrade to 1.83.7 or higher.

    Post summary

    CVE-2026-42208 in LiteLLM’s proxy was actively exploited within 36 hours of disclosure, with Bishop Fox reproducing the vulnerability and a remedial upgrade recommended.

    1411132.9K
    25.6K followersView on X
  • dbugs@ptdbugs
    Active Exploitation

    CVE-2026-42208: Why AI Gateways Are Becoming a New Attack Surface PT ID: PT-2026-35643 https://dbugs.ptsecurity.com/vulnerability/PT-2026-35643 The vulnerability CVE-2026-42208 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-42208) in LiteLLM Proxy exposed an issue that goes far beyond a conventional SQL injection. AI Gateways have become central points through which API keys, request routing, and authentication for multiple LLM providers are managed. The root cause was architectural. As the NefariousPlan investigation showed, the developers assumed that the "hashed_token" variable always contained a hash of the API key. However, in the "/key/block" and "/key/unblock" handlers, for keys without the "sk-" prefix, it received the unhashed value from the "Authorization: Bearer" header. The code then continued to treat it as a secure hash and used it to build an SQL query, resulting in an SQL injection vulnerability. The vulnerability affects LiteLLM Proxy versions 1.81.16–1.83.6 and allows an unauthenticated attacker to perform SQL injection through a specially crafted "Authorization: Bearer" header, potentially gaining access to the database and AI Gateway credentials. The issue is fixed in version 1.83.7 (updating to the latest stable version is recommended). As noted in the CriminalIP research, LiteLLM centrally stores cloud LLM provider keys, model routing configurations, and AI Gateway parameters. Therefore, successful exploitation effectively means the compromise of the entire AI infrastructure, not just the web application. Within 36 hours of the advisory's publication, the first exploitation attempts appeared, and CISA added CVE-2026-42208 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-42208) to the Known Exploited Vulnerabilities (KEV) catalog. However, the issue extends beyond a single CVE. Another Criminal IP study showed that thousands of AI Gateways and AI Relays are already exposed to the Internet and available for reconnaissance. As of July 2026, a search by HTML title using the CriminalIP service (queries such as "title: AI Gateway", "title: Claude API", "title: Claude Relay") identified more than 16,000 publicly accessible services. Many disclose information about the models (OpenAI, Claude, Gemini, DeepSeek), technologies in use (Nginx, Gunicorn), open ports, certificates, and management interfaces — information that makes it easier to identify known CVEs, misconfigurations, and weak authentication mechanisms. Article 1 (NefariousPlan's analysis of CVE-2026-42208): https://nefariousplan.com/posts/litellm-cve-2026-42208-hashed-token-was-a-parameter-name Article 2 (CriminalIP's brief analysis of CVE-2026-42208): https://www.criminalip.io/knowledge-hub/blog/34580 Article 3 (identifying AI Gateways in CriminalIP): https://www.criminalip.io/knowledge-hub/blog/35989 #dbugs_attacks

    Post summary

    LiteLLM Proxy’s CVE‑2026‑42208 allows unauthenticated SQL injection through a crafted Authorization header, exposing AI gateway credentials; exploitation attempts were observed within 36 hours of disclosure and the defect has been added to CISA’s KEV list, with a patch available in v1.83.7.

    2201201.2K
    3.5K followersView on X
  • Nate Robb@NateRobb
    Disclosure

    LiteLLM Proxy has a pre-auth SQL injection (CVE-2026-42208) I recently reproduced as part of @bishopfox's Emerging Threat process. Below is a technical analysis I put together with a safe detection payload that can be used to identify vulnerable deployments.

    Post summary

    The post discloses a pre‑authentication SQL injection in LiteLLM Proxy (CVE‑2026‑42208), reproduces it, and offers a detection payload for identifying vulnerable deployments.

    010581.5K
    197 followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    🚨New LiteLLM Flaw Exploited Shortly After Disclosure https://www.securityweek.com/fresh-litellm-vulnerability-exploited-shortly-after-disclosure/ LiteLLM is back in the headlines. A critical SQL injection flaw, CVE-2026-42208, was exploited a few days after disclosure. Attackers targeted database tables containing API keys, provider credentials, and environment variable configuration. The activity was fast and precise: exploitation was seen 36 hours after the advisory hit GitHub’s database, with attacks 21 minutes apart and rotating origin IPs. LiteLLM 1.83.7 fixes the issue. #LiteLLM #ThreatIntelligence #CyberSecurity #InfoSec

    Post summary

    CVE-2026-42208, a critical SQL injection in LiteLLM, was actively exploited within 36 hours of its disclosure, targeting database tables holding API keys and credentials; the issue is mitigated by the 1.83.7 release.

    020931.1K
    6.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    LiteLLM CVE-2026-42208 is under active exploitation. Attackers are using SQL injection to steal AI credentials. Patch to v1.83.7 and rotate keys immediately. #LiteLLM #SQLInjection #AISecurity #CVE #CyberSecurity #InfoSec #ExploitedInTheWild #PatchNow https://securityonline.info/litellm-sql-injection-exploited-in-the-wild-cve-2026-42208/ https://t.co/uEs9w32wf2

    Post summary

    The CVE‑2026‑42208 in LiteLLM is actively exploited via SQL injection to exfiltrate AI credentials; patch v1.83.7 and immediate key rotation are advised.

    12073787
    12.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/8追加) 🛡️No.1591 CVE-2026-42208 BerriAI LiteLLM SQL Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H LiteLLM Proxy の API キー検証処理において、呼び出し元が与えた値を SQL クエリに直接混在させていたことにより生じる SQL インジェクションの脆弱性が存在。事前認証されていない攻撃者により、細工した Authorization ヘッダーを任意の LLM API ルートに送信されることで、脆弱なデータベースクエリ経路に到達される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・LiteLLM Proxy の 1.81.16 以上 1.83.7 未満が稼働していること。 ・攻撃者が LiteLLM Proxy にネットワーク経由で到達可能であること。 ・認証は不要。 ✅悪用時影響 ・プロキシのデータベース内の情報を読み取られる ・データベース内容を改変され、プロキシおよびその管理する認証情報への不正アクセスにつながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み。Sysdig 脅威リサーチチームは、GitHub Advisory Database への登録から 36 時間 7 分後に最初の悪用試行を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-42208 https://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection https://www.sysdig.com/jp/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CVE‑2026‑42208 is a high‑severity SQL injection in LiteLLM Proxy, with a published PoC/exploit and confirmed in‑the‑wild attacks within 36 hours of disclosure, prompting its addition to the CISA KEV catalog.

    010925.9K
    43.9K followersView on X
  • 보안프로젝트@ngnicky
    Active Exploitation

    ⚡ LiteLLM SQL 인젝션 (CVE-2026-42208) — CVSS 9.3 공개 36시간 만에 야생 악용 시작. LiteLLM 프록시 DB 변조 가능. LLM 게이트웨이로 LiteLLM 쓰는 곳 즉시 업데이트. https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html

    Post summary

    LiteLLM is vulnerable to a high‑severity SQL injection (CVE‑2026‑42208) and attacks have begun in the wild within 36 hours of disclosure; users should urgently update.

    11072760
    6.8K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html

    Post summary

    CVE-2026-42208 in LiteLLM, a SQL injection flaw, was reportedly exploited within 36 hours of its disclosure, indicating active exploitation in the wild.

    020541.2K
    158.1K followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-42208: SQL Injection in LiteLLM, 9.3 rating 🔥 Pre-authentication SQL Injection in LiteLLM allows an attacker to read data from the proxy's database and modify it. This vulnerability is already being actively exploited in the wild! 👉 https://nt.ls/4MNkt

    Post summary

    CVE-2026-42208 is a high‑severity SQL injection in LiteLLM, rated 9.3, with confirmed reports of active exploitation in the wild.

    03033421
    7.4K followersView on X
  • dago@dagomint
    Active Exploitation

    CVE-2026-42208 — LiteLLM proxy actively exploited in the wild. Pre-auth SQL injection in the Authorization header. Attackers exfiltrating master keys + cloud provider credentials (OpenAI, Anthropic, AWS Bedrock). No auth required. This is what happens when your AI security depends on third-party proxies. https://getaibook.com/news/cve-2026-42208-pre-auth-sqli-actively-exploited-in-litellm/

    Post summary

    CVE-2026-42208 is a pre‑authentication SQL injection in LiteLLM’s Authorization header that is being actively exploited to steal master keys and cloud provider credentials, exploiting the lack of authentication.

    12050182
    436 followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure http://dlvr.it/TSwQKM #CyberSecurity #SQLInjection #CVE2026 #LiteLLM #Vulnerability https://t.co/LggVSkibrn

    Post summary

    The tweet reports that CVE‑2026‑42208, a SQL injection flaw in LiteLLM, was actively exploited within 36 hours of its disclosure, but no PoC, exploit code, or patch information is provided.

    03040816
    56.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure https://securityaffairs.com/191483/hacking/cve-2026-42208-litellm-bug-exploited-36-hours-after-its-disclosure.html?utm_source=dlvr.it&utm_medium=twitter #ArtificialIntelligence #BreakingNews #Hacking #Security

    Post summary

    CVE‑2026‑42208 in LiteLLM was reported to have been exploited within 36 hours of its disclosure, indicating active exploitation.

    01051608
    194.5K followersView on X
  • Alexander@AlexxTowers
    Active Exploitation

    1/5 LiteLLM CVE-2026-42208 pre-auth SQL injection exploited in <36 hours The LLM gateway used by thousands of AI agents has just become a credential harvester. No authentication required. Timeline, root cause, and exact controls that would have stopped it. This one hits the AI-agent routing layer hard. 🧵

    Post summary

    CVE-2026-42208, a pre‑auth SQL injection in LiteLLM, was reported as actively exploited within 36 hours, with no mitigation or patch mentioned.

    30031143
    39 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more