
🚨HIGH - LiteLLM Semantic Cache Tenant Isolation Bypass (CVE-2026-89032) BerriAI LiteLLM semantic cache mis-associates entries due to a metadata key mismatch, letting any authenticated user with a valid virtual key hit /v1/responses or /bedrock/* with semantically similar prompts to pull cached responses from other tenants. Impact: cross-tenant data leakage (PII/financial/source) and potential tool_calls/function_call replay causing agentic UIs to execute actions under victim creds. 👉Affected: litellm < 1.101.0-rc.1 | Upgrade to 1.101.0-rc.1
