LiteLLM has an authentication bypass via OIDC userinfo cache key collision
48Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.4epss 0.5%
de la publicación al arma43 días
Publicada en NVD6 abr
1ª PoC+43d
probabilidad de explotación
0.5%top 60% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This configuration option is not enabled by default. Most instances are not affected. An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token. On cache hit, the attacker inherits the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled. Fixed in v1.83.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Productos afectados
BerriAI · litellmPoCs públicas encontradas — 1
githubgithub.com/learner202649/CVE-2026-35030-PoC★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://access.redhat.com/errata/RHSA-2026:13545https://access.redhat.com/errata/RHSA-2026:28960https://access.redhat.com/errata/RHSA-2026:30056https://access.redhat.com/security/cve/CVE-2026-35030https://bugzilla.redhat.com/show_bug.cgi?id=2455509https://github.com/BerriAI/litellm/security/advisories/GHSA-jjhc-v7c2-5hh6https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35030.json