CVE-2026-42208

BerriAI LiteLLM — BerriAI LiteLLM SQL Injection Vulnerability

Severity
critical
Aktiv ausgenutzt
aktiv ausgenutzt (KEV)
99.7 %
Kritisch — Modell sagt sehr hohe Ausnutzungs-Wahrscheinlichkeit in den nächsten 30 Tagen.
Veröffentlicht
2026-05-08 04:16 UTC
CWE-89, CWE-89

Weakness-Klassen (CWE)

  • CWE-89Base

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

    cwe.mitre.org →
  • CWE-89Base

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Modified Analysis2026-06-29 17:18 UTC· nvd@nist.gov
    • Reference Type: redhat-SADP: https://access.redhat.com/security/cve/CVE-2026-42208 Types: Third Party Advisory
    • Reference Type: redhat-SADP: https://bugzilla.redhat.com/show_bug.cgi?id=2463965 Types: Mitigation, Third Party Advisory
    • Reference Type: redhat-SADP: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42208.json Types: Third Party Advisory

Beschreibung

BerriAI LiteLLM enthält eine SQL-Injection-Schwachstelle, die es einem Angreifer ermöglicht, Daten aus der Datenbank des Proxys zu lesen und möglicherweise zu ändern, was zu unbefugtem Zugriff auf den Proxy und die von ihm verwalteten Anmeldedaten führt.

Quelle: CISA_KEV

Öffentliche Exploit-Referenzen

Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.

Quellen & Referenzen

Verknüpfte Empfehlungen