CVE-2026-59822 – litellm
CVSS 8.2
IMPORTANT
Zero Day – Immediate Deployment
“A forged authorization path can turn failed authentication into unintended access.”
BerriAI fixed an authentication bypass in LiteLLM prior to version 1.84.0. CVE-2026-59822 affects the MCP Streamable HTTP endpoint, where a fabricated Authorization header could trigger an OAuth2 passthrough fallback and allow requests to reach MCP tooling without a valid LiteLLM key. The CVSS score is 8.8, which is High severity.
Active exploitation is confirmed. The issue is fixed in LiteLLM 1.84.0.
Key Details
- Affected Product
- Litellm Litellm
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-287
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.