Skip to content

Known CVE

LiteLLM - SQL Injection

LiteLLM 1.81.16 to < 1.83.7 contains a SQL injection caused by improper handling of caller-supplied key in database query during proxy API key checks, letting unauthenticated attackers read and modify database data, exploit requires crafted Authorization header.

CVE-2026-42208

Critical2026CVSS 9.8CWE-89

cve2026 · litellm · sqli · unauthenticated · kev · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website