DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84377: CVE-2026-84377: Server-Side Request Forgery and Provider Credential Exfiltration in LiteLLM Proxy

CVE-2026-84377: Server-Side Request Forgery and Provider Credential Exfiltration in LiteLLM Proxy

Vulnerability ID: CVE-2026-84377
CVSS Score: 6.5
Published: 2026-09-30

An authenticated Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in LiteLLM proxy prior to versions 1.88.6 and 1.96.2. By bypassing sanitization logic through nested form-data parameters or using connection health checks, authenticated users can redirect outbound API calls to arbitrary endpoints, exposing sensitive upstream administrative credentials.

TL;DR

Authenticated users can trigger SSRF and force LiteLLM to forward administrative API keys and cloud secrets to attacker-controlled servers via parameter manipulation.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-918
  • Attack Vector: Network
  • CVSS: 6.5
  • EPSS Score: 0.0054 (0.54%)
  • Impact: Server-Side Request Forgery & Credential Exfiltration
  • Exploit Status: Proof of Concept available
  • KEV Status: Not listed

Affected Systems

  • LiteLLM Proxy
  • LiteLLM: < 1.88.6 (Fixed in: 1.88.6)
  • LiteLLM: >= 1.89.0, < 1.96.2 (Fixed in: 1.96.2)

Code Analysis

Commit: 473f72e

Fix validation of bracket notation form parameters in request sanitization check

Commit: 820f247

Reject URL-valued model identifiers to prevent outbound server redirections

Commit: c898d34

Strip credentials from base configuration in connection health check overrides

Mitigation Strategies

  • Upgrade LiteLLM to patched versions (1.88.6 for LTS, 1.96.2 for mainline)
  • Deploy egress filtering rules to restrict the proxy's network access to authorized provider domains
  • Configure provider_url_destination_allowed_hosts in litellm_settings to prevent arbitrary URL connections
  • Perform rotative credential updates for all upstream provider keys managed by the proxy

Remediation Steps:

  1. Identify all deployed LiteLLM proxy containers or hosts
  2. Update the LiteLLM deployment manifest or configuration to point to version >= 1.96.2 or >= 1.88.6
  3. Apply the configuration change and restart the LiteLLM proxy instance
  4. Implement network egress blocklists to drop private network (RFC 1918) routing from the container
  5. Audit access logs for anomalous payloads containing bracket notation or external URL parameters

References


Read the full report for CVE-2026-84377 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)