CVE-2026-59822
HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Title source: cnaDescription
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
References (4)
Core 4
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/pull/26463
X_Refsource_Confirm x_refsource_confirm
https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/releases/tag/v1.84.0
Scores
CVSS v3
8.2
EPSS
0.0024
EPSS Percentile
15.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
CWE-306
Status
published
Products (3)
BerriAI/litellm
< 1.84.0
litellm/litellm
< 1.84.0
pypi/litellm
0 - 1.84.0PyPI
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026