CVE-2026-84377: Server-Side Request Forgery and Provider Credential Exfiltration in LiteLLM Proxy
Vulnerability ID: CVE-2026-84377
CVSS Score: 6.5
Published: 2026-09-30
An authenticated Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in LiteLLM proxy prior to versions 1.88.6 and 1.96.2. By bypassing sanitization logic through nested form-data parameters or using connection health checks, authenticated users can redirect outbound API calls to arbitrary endpoints, exposing sensitive upstream administrative credentials.
TL;DR
Authenticated users can trigger SSRF and force LiteLLM to forward administrative API keys and cloud secrets to attacker-controlled servers via parameter manipulation.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918
- Attack Vector: Network
- CVSS: 6.5
- EPSS Score: 0.0054 (0.54%)
- Impact: Server-Side Request Forgery & Credential Exfiltration
- Exploit Status: Proof of Concept available
- KEV Status: Not listed
Affected Systems
- LiteLLM Proxy
-
LiteLLM: < 1.88.6 (Fixed in:
1.88.6) -
LiteLLM: >= 1.89.0, < 1.96.2 (Fixed in:
1.96.2)
Code Analysis
Commit: 473f72e
Fix validation of bracket notation form parameters in request sanitization check
Commit: 820f247
Reject URL-valued model identifiers to prevent outbound server redirections
Commit: c898d34
Strip credentials from base configuration in connection health check overrides
Mitigation Strategies
- Upgrade LiteLLM to patched versions (1.88.6 for LTS, 1.96.2 for mainline)
- Deploy egress filtering rules to restrict the proxy's network access to authorized provider domains
- Configure provider_url_destination_allowed_hosts in litellm_settings to prevent arbitrary URL connections
- Perform rotative credential updates for all upstream provider keys managed by the proxy
Remediation Steps:
- Identify all deployed LiteLLM proxy containers or hosts
- Update the LiteLLM deployment manifest or configuration to point to version >= 1.96.2 or >= 1.88.6
- Apply the configuration change and restart the LiteLLM proxy instance
- Implement network egress blocklists to drop private network (RFC 1918) routing from the container
- Audit access logs for anomalous payloads containing bracket notation or external URL parameters
References
Read the full report for CVE-2026-84377 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)