← Back to Vulnerability Reports CVE Intelligence

CVE-2026-42208

BerriAI LiteLLMCRITICAL · CVSS 9.8 In the wild In CISA KEV

What is CVE-2026-42208?

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

CVSS9.8 NVD 3.1
SeverityCRITICAL
Exploitation In the wild In CISA KEV
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

BerriAI LiteLLM SQL Injection Vulnerability

Added to KEV2026-05-08
Federal patch deadline2026-05-11
Known ransomware useUnknown

Affected product

BerriAI LiteLLM

Remediation Steps

  1. Identify all systems running the affected software version
  2. Test patches in isolated lab environment before production deployment
  3. Deploy patches to production systems during change windows
  4. Verify patch installation across all affected systems
  5. Monitor system logs for exploitation attempts
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.