Skip to main content
UNKNOWN CISA KEV

CVE-2026-59822

CVSS v3

Unknown

EPSS Score

0.2 %

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

CISA Known Exploited Vulnerability

Date Added
2026-09-02
Patch Due Date
2026-09-16
Ransomware Use
Unknown

Technical details

Published
2026-07-08
Last Modified
2026-07-08
GitHub Advisory
GHSA-7488-6r32-c95q

Frequently asked questions

What is CVE-2026-59822?

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

Is CVE-2026-59822 actively exploited?

Yes. CVE-2026-59822 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2026-09-16.

What is the CVSS score for CVE-2026-59822?

A CVSS score has not been assigned to CVE-2026-59822 yet.

Is CVE-2026-59822 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key