Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_request_body_safe, which blocks top-level api_base and base_url but previously did not inspect or reject user_config. Because user_config constructs the outbound router, the nested destination redirects a server-side request to an internal or external host selected by the caller and can expose endpoints the caller cannot otherwise access. This issue is fixed in version 1.83.9.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery
Action: Patch
AI Analysis

Impact

LiteLLM, an AI‑Gateway proxy, allows an authenticated caller with a valid virtual key to embed an arbitrary api_base URL within the user_config payload. By bypassing the is_request_body_safe check, the proxy constructs outbound routing that can direct traffic to any internal or external host chosen by the attacker. This enables server‑side request forgery, allowing the proxy server to reach endpoints otherwise inaccessible, potentially leaking sensitive data or facilitating further internal compromise. The flaw is a CWE‑918 issue involving improper validation of input data.

Affected Systems

The vulnerability appears in the LiteLLM product from BerriAI. Versions earlier than 1.83.9 are impacted, including 1.83.8 and earlier. No other products or vendor versions are identified as affected.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity. The EPSS score indicates a very low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be limited to authenticated users possessing a valid virtual key, so the vector requires legitimate credential usage or credential compromise. The exploit path requires modifying the user_config data to redirect outbound calls, and although the risk is moderate, remediation is recommended to prevent internal data exposure or further compromise.

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LiteLLM to version 1.83.9 or later, which contains the patch for the SFR flaw.
  • If an upgrade is not immediately possible, disable or strictly validate the user_config parameter to reject any api_base entry within it.
  • Implement network segmentation or firewall rules to block the proxy from reaching internal hosts that should remain inaccessible, thereby limiting the potential impact of any residual vulnerabilities.

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hx8v-g79f-8w5f LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Berriai
Berriai litellm
Vendors & Products Berriai
Berriai litellm

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_request_body_safe, which blocks top-level api_base and base_url but previously did not inspect or reject user_config. Because user_config constructs the outbound router, the nested destination redirects a server-side request to an internal or external host selected by the caller and can expose endpoints the caller cannot otherwise access. This issue is fixed in version 1.83.9.
Title LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:07:47.837Z

Reserved: 2026-07-07T15:00:50.978Z

Link: CVE-2026-59823

cve-icon Vulnrichment

Updated: 2026-09-17T15:07:44.018Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:21.377

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-59823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)