LiteLLM: server-side request forgery
Medium6.5CVE-2026-84377 · Published Sep 30, 2026 · updated Oct 1, 2026
### Impact Any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination they control and cause the proxy to send its own configured provider credentials to that destination. The proxy's request-body validation was a denylist that did not cover every sensitive parameter and did not inspect parameters nested inside other request fields, so a caller could supply a routing or credential value that the proxy applied without clearing the operator's stored key. Any authenticated user could therefore exfiltrate the operator's upstream provider credentials and other configured secrets, and perform Server-Side Request Forgery against internal services reachable from the proxy. ### Patches Fixed in 1.96.2, 1.95.1, 1.94.3, 1.93.2, 1.92.2, 1.91.5, 1.90.7, 1.89.7, and 1.88.6. ### Workarounds Set `general_settings.allow_client_side_credentials` to `false` so callers cannot override connection parameters, restrict proxy keys to trusted callers, and block the affected parameters (`api_base`, `base_url`, `model_list`, `fallbacks`, provider credential fields) at a reverse proxy or API gateway.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | < 1.88.6 | 1.88.6 |
| >= 1.89.0, < 1.89.7 | 1.89.7 | |
| >= 1.90.0, < 1.90.7 | 1.90.7 | |
| >= 1.91.0, < 1.91.5 | 1.91.5 | |
| >= 1.92.0, < 1.92.2 | 1.92.2 | |
| >= 1.93.0, < 1.93.2 | 1.93.2 | |
| >= 1.94.0, < 1.94.3 | 1.94.3 | |
| >= 1.95.0, < 1.95.1 | 1.95.1 | |
| >= 1.96.0, < 1.96.2 | 1.96.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2026-84377, PYSEC-2026-4066
- github.com/BerriAI/litellm/security/advisories/GHSA-3cv6-jpf6-8222
- nvd.nist.gov/vuln/detail/CVE-2026-84377
- github.com/BerriAI/litellm/pull/36011
- github.com/BerriAI/litellm/pull/36314
- github.com/BerriAI/litellm/pull/36494
- github.com/BerriAI/litellm/commit/473f72e63a9777d793fbbf57194d8ec4fb97bc1b
- github.com/BerriAI/litellm/commit/820f247a6abba55cd87d130bef7bba7be3b29d37
- github.com/BerriAI/litellm/commit/c898d341c02299cf2506d0d8e84cc67953043593
- github.com/BerriAI/litellm
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | LiteLLM Proxy has server-side request forgery via the `user_config` request parameter | Medium | 1.83.9 |
| Aug 27 | LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint | Critical9.8 | 1.83.7 |
| Jul 22 | LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks | Low | 1.82.0 |
| Jul 22 | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | High | 1.84.0 |
| Jul 22 | LiteLLM: Local file read via request-supplied OIDC file references | Low | 1.83.10 |
| Jul 22 | LiteLLM: Arbitrary file write via path traversal in Skills archive extraction | Medium | 1.83.7 |