Skip to content
LiteLLMGHSA-hx8v-g79f-8w5f

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

MediumCVE-2026-59823 · Published Sep 17, 2026

### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_config` request body, bypassing the existing parameter guard. ### Details LiteLLM Proxy validates request bodies with `is_request_body_safe`, which blocks the `api_base` and `base_url` parameters but does not cover `user_config`. The `user_config` object is used to build the outbound router for a request, so a caller can place an `api_base` inside it and reach an arbitrary host. The guard only inspected the two top-level keys, so the same `api_base` nested inside `user_config` was never checked. Exploitation requires a valid virtual key. ### Impact An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access. ### Affected / Patched Affected: `<= 1.83.8` Patched: `1.83.9` ### Remediation Upgrade to 1.83.9 or later (released 2026-04-17).

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.83.91.83.9
Details and references

More LiteLLM advisories

All LiteLLM

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.