← back
CVE-2026-59822highobserved exploitationCWE-287CWE-306

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8.8epss 0.3%
from disclosure to weapon
Published on NVDJul 8
VulnCheck+18d
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
yesVulnCheck
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
BerriAI · litellm