CVE-2026-59822Active Exploitation(litellm / litellm)

HIGHCVSS 8.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-16. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-287CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 47 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 82 mentions across 29 observed days

What's happening

  • Active exploitation reported across 47 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 41 signals
  • Technical details provided in 63 signals
  • Disclosure: 12 classified signals
  • Peaked 21d ago at 10 mentions (2026-09-03); latest day: 1
  • 82 total mentions across 29 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline82 mentions / 29d
035810Mentions · 2026-07-08: 1Mentions · 2026-07-13: 1Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1Mentions · 2026-08-31: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 2Mentions · 2026-09-03: 10Mentions · 2026-09-04: 8Mentions · 2026-09-05: 3Mentions · 2026-09-06: 3Mentions · 2026-09-07: 5Mentions · 2026-09-08: 3Mentions · 2026-09-09: 7Mentions · 2026-09-10: 3Mentions · 2026-09-11: 7Mentions · 2026-09-12: 2Mentions · 2026-09-13: 1Mentions · 2026-09-14: 4Mentions · 2026-09-15: 7Mentions · 2026-09-17: 2Mentions · 2026-09-18: 1Mentions · 2026-09-19: 1Mentions · 2026-09-20: 2Mentions · 2026-09-28: 1Mentions · 2026-09-29: 1Mentions · 2026-10-02: 1Mentions · 2026-10-03: 1Mentions · 2026-10-04: 1PoC Mentioned / Linked · 2026-09-03: 1PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-12: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-03: 7Active Exploitation · 2026-09-04: 3Active Exploitation · 2026-09-05: 3Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-07: 4Active Exploitation · 2026-09-08: 2Active Exploitation · 2026-09-09: 7Active Exploitation · 2026-09-10: 1Active Exploitation · 2026-09-11: 2Active Exploitation · 2026-09-12: 1Active Exploitation · 2026-09-14: 4Active Exploitation · 2026-09-15: 4Active Exploitation · 2026-09-17: 2Active Exploitation · 2026-09-18: 1Active Exploitation · 2026-09-20: 2Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-03: 4Patch / Workaround · 2026-09-04: 7Patch / Workaround · 2026-09-05: 2Patch / Workaround · 2026-09-06: 2Patch / Workaround · 2026-09-07: 4Patch / Workaround · 2026-09-08: 3Patch / Workaround · 2026-09-09: 4Patch / Workaround · 2026-09-10: 1Patch / Workaround · 2026-09-11: 3Patch / Workaround · 2026-09-13: 1Patch / Workaround · 2026-09-14: 2Patch / Workaround · 2026-09-15: 3Patch / Workaround · 2026-09-17: 1Patch / Workaround · 2026-09-18: 1Patch / Workaround · 2026-09-19: 1Patch / Workaround · 2026-09-20: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-03: 8Technical Details · 2026-09-04: 6Technical Details · 2026-09-05: 3Technical Details · 2026-09-06: 3Technical Details · 2026-09-07: 5Technical Details · 2026-09-08: 3Technical Details · 2026-09-09: 6Technical Details · 2026-09-10: 3Technical Details · 2026-09-11: 4Technical Details · 2026-09-12: 2Technical Details · 2026-09-14: 4Technical Details · 2026-09-15: 4Technical Details · 2026-09-17: 2Technical Details · 2026-09-18: 1Technical Details · 2026-09-19: 1Technical Details · 2026-09-20: 207-0808-2808-3109-0209-0409-0609-0809-1009-1209-1409-1709-1909-2810-0210-04
Signal classification4 categories
Active Exploitation
4457.1%
Patch
1722.1%
Disclosure
1215.6%
General
45.2%
Referenced assets45 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-131
Disclosure1
2026-08-281
Active Exploitation1
2026-08-301
Active Exploitation1
2026-08-311
Disclosure1
2026-09-011
Active Exploitation1
2026-09-022
Disclosure1General1
2026-09-0310
Active Exploitation7Disclosure1Patch2
2026-09-048
Active Exploitation2Disclosure1Patch5
2026-09-053
Active Exploitation3
2026-09-063
Active Exploitation1Disclosure1Patch1
2026-09-075
Active Exploitation4Disclosure1
2026-09-083
Patch3
2026-09-097
Active Exploitation7
2026-09-103
Active Exploitation1Disclosure1Patch1
2026-09-117
Active Exploitation2General3Patch2
2026-09-122
Active Exploitation1Disclosure1
2026-09-131
Patch1
2026-09-144
Active Exploitation4
2026-09-157
Active Exploitation4Disclosure2Patch1
2026-09-172
Active Exploitation2
2026-09-181
Active Exploitation1
2026-09-191
Patch1
2026-09-202
Active Exploitation2
Full discourse20 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨CVE-2026-59822 (CVSS 8.2): LiteLLM Authentication Bypass 📊 510K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22litellm%22 HUNTER : http://product.name="litellm" 📰Refer:https://github.com/BerriAI/litellm/pull/26463 https://www.wiz.io/blog/ai-infrastructure-honeypot https://blog.codercops.com/blog/litellm-mcp-auth-bypass-cve-2026-59822 https://www.scorifya.com/cve/CVE-2026-59822 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The alert announces CVE‑2026‑59822 (an authentication bypass in LiteLLM with CVSS 8.2) and provides links to documentation and a GitHub patch, but does not mention active exploitation or exploit code.

    38034144.5K
    26.1K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-59822 (CVSS 8.8): Authentication bypass in LiteLLM AI Gateway — unauthenticated MCP Streamable HTTP session via arbitrary Bearer token, actively exploited in AI infra attacks 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJMaXRlTExNLUFQSSI= 🎯80.6K+ internet-facing LiteLLM surfaces are found on http://en.fofa.info in the past year. FOFA Query: app="LiteLLM-API" 🔖Refer: https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑59822 is an authentication bypass in LiteLLM AI Gateway, with a CVSS of 8.8, and is actively exploited in AI infrastructure attacks, as confirmed by a CISA alert and a large number of internet‑facing instances discovered via FOFA.

    2903984.0K
    14.8K followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    Active Exploitation

    CVE-2026-59822. CISA just added this one to its Known Exploited Vulnerabilities catalog, and the bug itself should scare anyone running MCP servers in production. It's an auth bypass in LiteLLM's MCP Streamable HTTP endpoint. CVSS 8.8. Here's what's wild: the OAuth2 passthrough was broken so badly that you could send an arbitrary Bearer token, any string, and still get a fully authenticated Model Context Protocol (MCP) session. Wiz ran a 90-day honeypot and caught attackers testing this with single-character tokens. Not stolen credentials. Not cracked JWTs. Just "a". Once inside, they didn't stop at recon. They ran crypto miners and tried blind prompt injection against whatever agent was sitting behind the MCP server. Why does this matter more than a normal auth bug? Because MCP is the layer that hands your agent tools: read this inbox, call this API, touch this database. If the front door doesn't check who's knocking, every tool behind it is exposed for free. Building agents that connect through MCP servers? Check how your gateway validates tokens. BEFORE (dangerous): MCP server receives a Bearer token from the client and forwards it downstream, trusting that a token was present at all, never checking it against the auth server. AFTER (safe): validate token signature, issuer, audience, and expiry against your OAuth provider before a session opens. Reject anything that doesn't match. Log every rejected handshake. Patched in LiteLLM 1.84.0. Federal remediation deadline is 2026-09-16. If you're running LiteLLM as an MCP gateway for a support bot, an internal tools agent, anything, have you actually checked your version number today? #MCP #PromptInjection #AISecurity

    Post summary

    CVE‑2026‑59822 is an authentication bypass in LiteLLM’s MCP that is actively exploited, as highlighted by CISA’s Known Exploited Vulnerabilities catalog and honeypot data, and has been patched in LiteLLM 1.84.0.

    100072636
    1.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🔴 LiteLLM / MCP açığı: CVE-2026-59822 — CISA KEV'e eklendi LiteLLM'in MCP Streamable HTTP endpoint'inde ciddi bir kimlik doğrulama atlatma açığı bulunuyordu. Saldırganın geçerli bir API/OAuth token'ına sahip olması gerekmiyor, savunmasız sürümlerde rastgele bir Bearer token göndererek MCP oturumu açmak mümkündü. Örneğin: Authorization: Bearer a ➡️ Kimlik doğrulama atlatılabiliyor ➡️ MCP araçlarına yetkisiz erişim sağlanabiliyor ➡️ MCP arkasındaki API, veritabanı, e-posta veya diğer araçlar risk altına girebiliyor. ⚠️ CISA, CVE-2026-59822'yi KEV kataloğuna ekledi. Bu, açık halen aktif olarak istismar ediliyor. Etkilenen: LiteLLM < 1.84.0 Çözüm: LiteLLM 1.84.0 veya üzeri ⚠️ Özellikle internete açık MCP gateway'leri acilen kontrol edilmeli. MCP kullanan LiteLLM sistemlerinde mesele yalnızca AI modeli değil; agent'ın erişebildiği tüm araçlar risk altında olabilir.

    Post summary

    CVE-2026-59822 is an authentication bypass in LiteLLM’s MCP endpoint that is actively exploited in the wild, is listed in CISA’s KEV catalog, and is fixed in version 1.84.0 and later.

    020104758
    2.4K followersView on X
  • Samuel McDonnell@samueljmcd
    Active Exploitation

    CISA just put LiteLLM and Starlette on the Known Exploited list. CVE-2026-59822: on LiteLLM before 1.84.0, a failed API-key check falls through to an empty auth object. Any Bearer token can open an authenticated MCP Streamable HTTP session. CVE-2026-48710: one bad character in the Host header (/, ?, #) and Starlette rebuilds the path wrong, so path-based auth middleware can be skipped. That stack sits under a lot of vLLM, LiteLLM, and MCP servers. Patch the gateway. Don't wait for the model layer to save you.

    Post summary

    The post highlights two CVEs in LiteLLM and Starlette as known exploited, explains their exploitation mechanisms, and urges immediate patching of the gateway.

    30090816
    4.3K followersView on X
  • Hazem Omier@hazemomier
    Active Exploitation

    Your LLM gateway holds the keys. Treat it like one. CVE-2026-59822 (LiteLLM MCP auth bypass) is in CISA KEV with real exploitation. Fail-open OAuth fallback → empty auth object → the gateway stops asking who is calling. Internet-facing LiteLLM: patch to 1.84.0+, rotate provider keys, put an independent auth layer in front. One check that fails open is not a boundary.

    Post summary

    The post reports that CVE-2026-59822 (LiteLLM MCP auth bypass) is listed in CISA KEV with real-world exploitation, explains the fail-open OAuth fallback flaw, and urges immediate patching to version 1.84.0+ along with key rotation and an independent authentication layer.

    31020108
    467 followersView on X
  • H1DR4@H1DR4_agent
    Active Exploitation

    Signal — 14 Sep 2026 CISA says CVE-2026-59822 is being actively exploited. It affects LiteLLM's MCP Streamable HTTP endpoint. Federal remediation deadline: 16 Sep. This is not a theoretical prompt-injection issue. It is an authentication failure. 1/7

    Post summary

    CISA reports CVE-2026-59822 is actively exploited, affecting LiteLLM's MCP Streamable HTTP endpoint, with a federal remediation deadline of September 16, 2026; it is an authentication failure, not a prompt‑injection issue.

    10130385
    3.4K followersView on X
  • YourDailyCVE@YourDailyCVE
    Patch

    🚨 CVE-2026-59822 — LiteLLM. A fake Authorization header walks straight past the login. Disclosed Jul 8. What broke: LiteLLM is the bouncer that checks API keys before requests reach your AI tools. When key validation fails, it is supposed to say no. Instead, a fallback path meant for OAuth2 passthrough quietly swaps the failed key for an empty identity and waves the request through. An attacker just makes up an Authorization header — any string — and reaches MCP tooling with no valid key at all. Who should care: anyone running LiteLLM (the open-source LLM proxy / AI gateway) below version 1.84.0 with the MCP Streamable HTTP endpoint enabled. If your company routes AI traffic through LiteLLM, that is you. Why that matters: MCP tools are where the AI touches real things — databases, files, internal APIs, code execution. Walking past the bouncer means a stranger on the internet can call those tools through your gateway, read what they return, and burn your model credits doing it. Confirmed impact: high confidentiality hit, some integrity hit. Status: public since July 8, fix shipped same day in 1.84.0. CVSS 4.0 score 8.8 (High). Exploit likelihood scored low (EPSS <1%), though at least one tracker flags it as exploited. Not on CISA KEV as of Sep 3. Intelligence still being updated as of yesterday. Fix today: upgrade LiteLLM to 1.84.0 or later. Advisory GHSA via BerriAI/litellm. Can't patch: block or disable the MCP Streamable HTTP endpoint at the proxy/WAF until you can upgrade. If the box was internet-facing, rotate every API key and secret the gateway holds — a bypass means they may already be gone. Source: GitHub Security Advisory (BerriAI/litellm) / NVD CVE-2026-59822 #LiteLLM #AISecurity #MCP

    Post summary

    CVE-2026-59822 allows an attacker to bypass LiteLLM’s API key checks by sending a fabricated Authorization header, enabling access to sensitive MCP tools. The vulnerability is mitigated by upgrading to LiteLLM 1.84.0 or disabling the MCP Streamable HTTP endpoint.

    10021232
    34 followersView on X
  • Tochukwu Okonkwor@tokonkwor
    Active Exploitation

    Details for anyone checking their own estate. CVE-2026-59822. An authentication bypass in the tool-calling endpoint: a fallback path accepted a fabricated bearer token where key validation had failed. Rated 8.8 under the current scoring version and 8.2 under the previous one, weighted toward confidentiality rather than clean code execution, because what it reaches is keys and tools. Observed in the wild: provider key extraction, a cryptominer, and modified authorised_keys for persistence. The fix shipped in May. If your platform team stood this up quickly and outside the normal change process, which many did deliberately, nobody may be tracking the version. Rotate every key the gateway could reach, not just the one you think leaked.

    Post summary

    The tweet reports CVE-2026-59822, an authentication bypass with CVSS 8.8/8.2, confirms active exploitation in the wild, mentions a May patch, and urges rotating all gateway keys.

    2001056
    25 followersView on X
  • E@ethanxpy
    Active Exploitation

    LiteLLM CVE-2026-59822 isn’t “AI went rogue.” MCP endpoint: bad Bearer → OAuth2 fallback → empty auth. Fake token = session. CISA KEV after real exploitation. Miss is fail-open gateway auth. Patch 1.84.0+. Fear the /mcp route, not the model.

    Post summary

    The text confirms CVE-2026-59822 is on the CISA KEV catalog following real-world exploitation, describes the fail-open auth flaw on the /mcp endpoint, and notes Patch 1.84.0+ as the fix.

    2001085
    125 followersView on X
  • ISSA@prunier_issa
    Disclosure

    CISA just put an AI agent gateway on the must-patch list. CVE-2026-59822. A fake token was enough to hijack an MCP session and reach the tools behind it "We shipped rails for agents. We skipped brakes" That’s the gap Shotoku is built for.

    Post summary

    The text announces CVE‑2026‑59822 as a must‑patch AI agent gateway issue with a token hijack vulnerability but provides no PoC, exploit, or patch details.

    0102076
    78 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    LiteLLM auth bypass chains to root-level RCE and IAM credential theft. CVE-2026-59822 is actively exploited in the wild and now on CISA KEV, present in roughly one-third of cloud environments. Key findings: - CVE-2026-59822 (MCP auth bypass): the MCP auth handler in user_api_key_auth_mcp.py catches 401s from invalid tokens and returns an empty UserAPIKeyAuth() object, granting a fully authenticated session. A single request with "Authorization: Bearer a" is enough. Honeypot data confirmed active exploitation as of 2026-07-07. Fix landed in v1.84.0. - CVE-2026-59821 (post-auth RCE): the guardrail registration endpoint (POST /guardrails) called exec(compile(...)) without stripping __builtins__ or running the forbidden-patterns check, giving submitted Python the full standard library. Code executed at registration time, not inference time. Fixed in v1.82.0 with sandbox enforcement and PROXY_ADMIN gating. - 9.6% of 3,074 scanned public instances accepted the default master key (sk-1234) or required no auth. Pre-patch, no-auth deployments granted PROXY_ADMIN to every request by default. Chaining default key plus CVE-2026-59821 (pre-v1.82.0) yields pre-auth root in one request. - Pass-through endpoints proxy requests to arbitrary URLs with no validation, including AWS IMDS. The x-pass- header prefix strips and forwards headers to the target, defeating IMDSv2 protections and enabling IAM credential exfiltration post-auth. #DFIR_Radar

    Post summary

    The post confirms CVE-2026-59822 is being actively exploited in the wild, provides detailed technical explanations of the vulnerability, and notes available patches—all underscoring widespread real‑world threat.

    30000196
    1.9K followersView on X
  • The Agentic Daily@theagenticdaily
    Active Exploitation

    A critical bug in LiteLLM lets attackers skip authentication and call MCP tools directly - CVE-2026-59822, CVSS 8.8, now on CISA's Known Exploited Vulnerabilities list. Anyone routing AI agents through LiteLLM should upgrade to v1.84.0 or later immediately; it can also be chained with a separate command-injection bug (CVE-2026-42271).

    Post summary

    The post announces a critical, actively exploited vulnerability in LiteLLM, urging immediate upgrade to mitigate the risk.

    10020148
    94 followersView on X
  • Er Sonu Saini | DevOps & AI@ErSonusaini1
    Patch

    Running LiteLLM as your LLM gateway? Patch today ⚠️ CVE-2026-59822 (CVSS 8.8): MCP auth bypass — unauthenticated callers can invoke your MCP tools. Actively exploited &amp; on CISA's KEV list. Fix: upgrade to v1.84.0+ https://nvd.nist.gov/vuln/detail/cve-2026-59822 #DevOps #Security #LLM

    Post summary

    CVE-2026-59822 is an unauthenticated MCP auth bypass in LiteLLM with a CVSS of 8.8, actively exploited and listed on CISA’s KEV; users are urged to patch by upgrading to v1.84.0+.

    10110235
    120 followersView on X
  • Caldura@Caldura7
    Disclosure

    CISA KEV: CVE-2026-59822 LiteLLM MCP auth bypass. Fake bearer token opens an authenticated MCP session. Wiz saw probes against model enumeration endpoints. #cybersecurity #infosec #CISA #KEV #AIsecurity https://t.co/bxBtUIDzC2

    Post summary

    The tweet announces the CISA KEV CVE‑2026‑59822, highlighting a LiteLLM authentication bypass via fake bearer tokens and noting probing activity, but it provides no PoC, exploit code, or patch information.

    1001149
    60 followersView on X
  • Marcell Ujlaki@UjlakiMarci
    Disclosure

    🟧 [Score Added] CVE-2026-59822 | Litellm, CVSS: 8.8 (#High) a security flaw in how the software handles authentication requests (in the MCP Streamable HTTP endpoint) that allows an unauthorized person to bypass security controls when authentication fails, the system incorrectly defaults to a fallback mode that allows requests to proceed without a valid key an attacker could potentially access restricted tooling or services without providing valid credentials https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c

    Post summary

    CVE-2026-59822 highlights an authentication bypass flaw in Litellm’s MCP Streamable HTTP endpoint, permitting unauthorized access without credentials, with a high CVSS score of 8.8.

    20010231
    354 followersView on X
  • Diego Pepe@diegopepe10
    Patch

    @JGamblin Exactly. CVE-2026-59822 is on that list. Patch to 1.84.0 is necessary and not sufficient: inventory every MCP server on the proxy, then rotate the keys it stored.

    Post summary

    The tweet stresses that CVE-2026-59822 requires patching to version 1.84.0 and key rotation, but it offers no exploit code, technical depth, or evidence of active exploitation.

    1001044
    69 followersView on X
  • InfraSecurity Services@infrasecserv
    Active Exploitation

    CISA KEV: attackers are chaining CVE-2026-59822 (LiteLLM MCP auth bypass) with CVE-2026-48710 (Starlette host header) for unauthenticated RCE on AI gateways. Qilin ransomware linked. Federal patch deadline Sept 16. Inventory your AI gateways. #InfoSec #ZeroDay #AISecurity

    Post summary

    CISA flags active exploitation of two CVEs (LiteLLM MCP auth bypass and Starlette host header) chaining to achieve unauthenticated RCE on AI gateways, with Qilin ransomware linked; a federal patch deadline of September 16 is announced.

    2000090
    12 followersView on X
  • Peldum@peldumHack
    Patch

    4/ Caso concreto — LiteLLM, CVE-2026-59822: en versiones &lt; 1.84.0, un Bearer inventado podía abrir una sesión MCP “autenticada”. Traducción: listar y llamar tools conectados sin key válida. Fix: ≥ 1.84.0. Si no podés actualizar ya, cortá las rutas `/mcp/`.

    Post summary

    The advisory announces CVE‑2026‑59822 for LiteLLM versions below 1.84.0, explaining that a bogus Bearer token can access MCP APIs without authentication, and recommends upgrading to 1.84.0 or blocking `/mcp/` routes.

    2000053
    582 followersView on X
  • Echosphere@Echosphere8f
    Patch

    「認証に失敗した」のに、空の権限オブジェクトが残る。失敗が通行証になる設計だ。💎 LiteLLM、CVE-2026-59822。MCP Streamable HTTPで偽Bearerを投げると、キー検証失敗→OAuth2パススルーfallbackへ落ちて、空のUserAPIKeyAuth()が残る。未認証でMCPツールに届く。修正は1.84.0。 https://github.com/advisories/GHSA-7488-6r32-c95q #LiteLLM #MCP 噛み砕く。Wizのハニーポットでも観測されてる。Bearerに「x」一文字でも通る経路があった、と報告側が書いてる。⚠️ https://www.wiz.io/blog/ai-infrastructure-honeypot フォールバックは「別の正しい証明」へ繋ぐものだ。「失敗したら空っぽで通す」はフォールバックじゃねぇ。fail-openだぜ。 やることは単純だ。1.84.0以上へ上げろ。すぐ無理なら /mcp/ を外から切れ。ゲートウェイに鍵を積むなら、失敗時の出口も境界だ。 「たぶん大丈夫」で残した空オブジェクトは、いつか誰かの入口になる。 contr。 https://nvd.nist.gov/vuln/detail/CVE-2026-59822 #LLMSecurity #CVE -- メル

    Post summary

    The post discloses CVE‑2026‑59822 details, reports real‑world usage via a honeypot, and recommends patching to 1.84.0 or blocking access.

    10010216
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more