CRITICAL🇵🇱 Wersja polska

CVE-2026-35030

CVSS 9.4v4.0pub. 2026-04-06upd. 2026-06-30

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This configuration option is not enabled by default. Most instances are not affected. An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token. On cache hit, the attacker inherits the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled. Fixed in v1.83.0.

🤖 AI Analysis
How it works

When 'enable_jwt_auth: true' is enabled, the OIDC userinfo cache mechanism uses only the first 20 characters of the token (token[:20]) as the cache key. JWT tokens signed with the same algorithm can generate identical first 20 characters. An attacker can craft a token whose first 20 characters match the token of a legitimate user already in the cache. In case of a cache hit, the attacker assumes the identity and permissions of that user without needing to possess valid credentials.

Impact

An attacker gains unauthorized access to resources and functionalities available to a legitimate user, potentially including full control over external systems (SC:H/SI:H) with which LiteLLM integrates as an AI Gateway.

Mitigation & patch

LiteLLM should be updated to version 1.83.0 or later, which fixes the cache key generation mechanism. Until the update is applied, as a workaround, disabling the 'enable_jwt_auth' option can be considered if it is not strictly required.

Who is affected

LiteLLM (product by BerriAI) in versions earlier than 1.83.0, only in configurations with the 'enable_jwt_auth: true' option enabled. This option is not active by default, which limits the scope of the vulnerability.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Litellm

    APP
    Litellm
    < 1.83.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-42208CRITICAL9.3⚠ KEVPL ✓same product

SQL Injection w LiteLLM umożliwia nieautoryzowany dostęp do bazy danych

CVE-2026-33634CRITICAL9.4⚠ KEVPL ✓same product

Atak supply chain na Trivy — złośliwe tagi GitHub Actions i obraz kontenera

CVE-2026-49468CRITICAL9.5PL ✓same product

LiteLLM: pominięcie uwierzytelnienia przez manipulację nagłówkiem Host

CVE-2024-5751CRITICAL9.8PL ✓same product

RCE w BerriAI/litellm poprzez endpoint /config/update

CVE-2024-2952CRITICAL9.8PL ✓same product

BerriAI LiteLLM – SSTI via Jinja umożliwia RCE przez endpoint /completions