CVE-2026-59822 – litellm

CVSS 8.2 IMPORTANT Zero Day – Immediate Deployment

“A forged authorization path can turn failed authentication into unintended access.”

BerriAI fixed an authentication bypass in LiteLLM prior to version 1.84.0. CVE-2026-59822 affects the MCP Streamable HTTP endpoint, where a fabricated Authorization header could trigger an OAuth2 passthrough fallback and allow requests to reach MCP tooling without a valid LiteLLM key. The CVSS score is 8.8, which is High severity.

Active exploitation is confirmed. The issue is fixed in LiteLLM 1.84.0.

Key Details

Affected Product
Litellm Litellm
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.