AllCyberNews

CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

CVSS 8.8 high · BerriAI litellm · published 2026-07-08

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

Coverage 1 source

  1. 2026-09-02 CISA Cybersecurity Advisories high CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog.

Mentioned with

CVE-2026-48710 CVE-2026-49869 CVE-2026-82329 CVE-2026-9586

Also covered