Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityidentity-authentication-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerability

Critical LiteLLM Host Header Flaw Enables Authentication Bypass

Updated 2d agoFirst seen Jun 17, 20262 sources

A critical vulnerability in LiteLLM tracked as CVE-2026-49468 allows attackers to bypass authentication through Host header injection and reach protected management endpoints. The flaw affects LiteLLM versions earlier than 1.84.0 and stems from a mismatch in how the authentication layer evaluates routes versus how FastAPI ultimately dispatches them, creating a path for unauthenticated access under specific conditions. The issue is classified as CWE-290 and has been rated CVSS 9.5, with researchers describing it as network-exploitable with low attack complexity and no user interaction required.

The vulnerability was responsibly disclosed by Le The Thang of KCSC and Kim Ngoc Chung of One Mount Group, and LiteLLM maintainers have released a fix in version 1.84.0 with no configuration changes required. There is no confirmed evidence of active exploitation, and LiteLLM Cloud customers are reportedly not affected. Self-hosted deployments may also be shielded if upstream infrastructure such as Cloudflare, WAFs, reverse proxies with strict allowlists, or host-validating load balancers normalize or reject malformed Host headers before requests reach the application.

Share:
Critical LiteLLM Host Header Flaw Enables Authentication Bypass
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 17, 20264d ago

CVE-2026-49468 publicly disclosed for LiteLLM

The critical vulnerability CVE-2026-49468 was publicly disclosed as affecting LiteLLM versions before 1.84.0, with potential unauthenticated access to protected management endpoints under specific deployment conditions. Reports noted no confirmed exploitation at the time of disclosure.

Critical LiteLLM Vulnerability Let Attackers Bypass Authentication via Host Header Injection

LiteLLM fixes CVE-2026-49468 in version 1.84.0

LiteLLM patched the Host header injection authentication bypass vulnerability in version 1.84.0. The fix does not require configuration changes, and LiteLLM Cloud customers were reported as unaffected.

Critical LiteLLM Vulnerability Let Attackers Bypass Authentication via Host Header Injection

Researchers report LiteLLM auth bypass vulnerability

Le The Thang of KCSC and Kim Ngoc Chung of One Mount Group responsibly reported CVE-2026-49468, an authentication bypass flaw in LiteLLM caused by Host header injection and route handling discrepancies.

Critical LiteLLM Vulnerability Let Attackers Bypass Authentication via Host Header Injection
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
4 linked
LitellmCloudflareStarletteLitellm
Organizations
3 linked
One Mount GroupCloudflareSecurityOnline.info
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.