CVE-2026-35030: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token...

Added to the CISA Known Exploited Vulnerabilities catalog on 06 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.1.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first ...

Required action: Review and patch if applicable to your AI infrastructure.