CVE-2026-42208
BerriAI LiteLLM SQL Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.3
- EPSS
- 83.5% 백분위 99.6% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2026.05.11
- 공개일
- 2026.05.08
CISA KEV에 등록된 실제 악용 확인 취약점
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised acc...
공급사 BerriAI
제품 litellm, Lightspeed Core, Red Hat Ansible Automation Platform 2
영향 버전 >= 1.81.16, < 1.83.7, >= 1.81.16 < 1.83.7
수정 버전 1.83.7
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.05.11CVSS 벡터 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE CWE-89
KEV 등록일 2026.05.08
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc ; https://nvd.nist.gov/vuln/detail/CVE-2026-42208
EPSS 데이터 기준일 2026.06.27