CVE-2026-59819: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and O...

Added to the CISA Known Exploited Vulnerabilities catalog on 08 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.9.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another privileged caller w...

Required action: Review and patch if applicable to your AI infrastructure.