CVE-2026-12796: falha de média gravidade em BerriAI litellm
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
Publicada em · Atualizada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 0.6%
probabilidade de exploração
0.6%top 55% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
BerriAI · litellmPoCs públicas encontradas — 1
cve_referencegist.github.com/YLChen-007/5fa8af12e1b183674d7ca96d852fb697não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — BerriAI litellm
No mesmo produto, das mais perigosas para as menos.
CVE-2026-42271HIGHLiteLLM: Authenticated command execution via MCP stdio test endpointsEPSS 92.6%KEVCVE-2026-42208CRITICALLiteLLM: SQL injection in Proxy API key verificationEPSS 5.8%KEVCVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.8%KEVCVE-2026-35029HIGHLiteLLM affected by privilege escalation via unrestricted proxy configuration endpointEPSS 4.0%CVE-2026-49468CRITICALLiteLLM: Authentication Bypass via Host Header InjectionEPSS 3.0%CVE-2026-47101HIGHLiteLLM < 1.83.14 Privilege Escalation via API Key GenerationEPSS 1.3%