CVE-2026-84377 | BerriAI LiteLLM up to 1.88.5/1.96.1 Request Validation auth_utils.py server-side request forgery
A vulnerability marked as problematic has been reported in BerriAI LiteLLM up to 1.88.5/1.96.1. This vulnerability affects unknown code of the file litellm/proxy/auth/auth_utils.py of the component Request Validation. This manipulation of the argument api_base/base_url/model_list/fallbacks/litellm_credential_name causes server-side request forgery.
The identification of this vulnerability is CVE-2026-84377. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More