CVE-2026-49468: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauth...
Added to the CISA Known Exploited Vulnerabilities catalog on 22 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from req...
Required action: Review and patch if applicable to your AI infrastructure.