CVE-2026-59822

HIGH

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Title source: cna
STIX 2.1

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

Scores

CVSS v3 8.2
EPSS 0.0024
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (3)
BerriAI/litellm < 1.84.0
litellm/litellm < 1.84.0
pypi/litellm 0 - 1.84.0PyPI
Published Jul 08, 2026
Tracked Since Jul 09, 2026