LiteLLM MCP Streamable HTTP improper auth (CVE-2026-59822); CISA KEV
BerriAI LiteLLM GHSA-7488-6r32-c95q (CVE-2026-59822) is High: the MCP Streamable HTTP auth path could let an unauthenticated attacker establish an MCP session with an arbitrary Bearer token when OAuth2 passthrough fallback replaced failed key validation with an empty UserAPIKeyAuth object, exposing configured MCP tools and connected services. Affected versions before 1.84.0; fixed in 1.84.0. GHSA publishes CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N; CISA KEV (2 Sep 2026) and The Hacker News cite 8.8. CISA added the CVE to KEV on evidence of active exploitation. Upgrade to 1.84.0+ or disable/block /mcp/ until patched.
- Product
- BerriAI LiteLLM
- Versions
- Affected before 1.84.0; fixed in 1.84.0
- CVSS
- High (CISA KEV / THN); GHSA CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- LiteLLM 1.84.0 or later; or disable/block MCP routes
Primary: GitHub GHSA-7488-6r32-c95q (LiteLLM) · Vendor: BerriAI LiteLLM (vendor advisory) · CVE: CVE-2026-59822 · CISA KEV alert (2 Sep 2026)
