Critical severity9.8GHSA Advisory· Published Jun 22, 2026· Updated Jul 15, 2026
CVE-2026-49468
CVE-2026-49468
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from request.url.path in litellm/proxy/auth/auth_utils.py::get_request_route(), which Starlette reconstructs from the Host header. A crafted Host could therefore make the auth gate evaluate a different route from the one FastAPI dispatched. This vulnerability is fixed in 1.84.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
litellmPyPI | < 1.84.0 | 1.84.0 |
Affected products
5- osv-coords3 versions
< 2.11.2-r12+ 2 more
- (no CPE)range: < 2.11.2-r12
- (no CPE)range: < 3.2.2-r7
- (no CPE)range: < 3.2.2-r7
Patches
Vulnerability mechanics
References
9- github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3wnvdMitigationPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-4xpc-pv4p-pm3wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-49468ghsaADVISORY
- access.redhat.com/security/cve/CVE-2026-49468nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/BerriAI/litellm/releases/tag/v1.84.0nvdProductRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/litellm/PYSEC-2026-388.yamlghsaWEB
- pypi.org/project/litellmghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49468.jsonnvdWEB
News mentions
2- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Critical LiteLLM Flaw Allows Authentication Bypass via Host Header InjectionCyber Security News · Jun 17, 2026