Vulnerability
Published 2026-09-02
Verified 2026-09-19

LiteLLM MCP Streamable HTTP improper auth (CVE-2026-59822); CISA KEV

BerriAI LiteLLM GHSA-7488-6r32-c95q (CVE-2026-59822) is High: the MCP Streamable HTTP auth path could let an unauthenticated attacker establish an MCP session with an arbitrary Bearer token when OAuth2 passthrough fallback replaced failed key validation with an empty UserAPIKeyAuth object, exposing configured MCP tools and connected services. Affected versions before 1.84.0; fixed in 1.84.0. GHSA publishes CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N; CISA KEV (2 Sep 2026) and The Hacker News cite 8.8. CISA added the CVE to KEV on evidence of active exploitation. Upgrade to 1.84.0+ or disable/block /mcp/ until patched.

Product
BerriAI LiteLLM
Versions
Affected before 1.84.0; fixed in 1.84.0
CVSS
High (CISA KEV / THN); GHSA CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Exploited in Australia?
unknown
Patch to
LiteLLM 1.84.0 or later; or disable/block MCP routes

Primary: GitHub GHSA-7488-6r32-c95q (LiteLLM) · Vendor: BerriAI LiteLLM (vendor advisory) · CVE: CVE-2026-59822 · CISA KEV alert (2 Sep 2026)

vulnerabilities cloud ai