Skip to content
LiteLLMGHSA-mf52-j94g-746m

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

Low6.3CVE-2026-12772 · Published Jun 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.82.2No fix yet
Details and references

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-613
Also known as
CVE-2026-12772

More LiteLLM advisories

All LiteLLM
DateAdvisory
Jun 21LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12770Low5.4no fix yet
Jun 21LiteLLM: M2M JWT Handler Has Improper Authorization
CVE-2026-12771Low5.0no fix yet
Jun 21LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12773Medium7.3fixed in 1.84.0
Jun 21LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12795Medium7.3no fix yet
Jun 21BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12798Low6.3no fix yet
Jun 21BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
CVE-2026-12799Low4.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.