All verified exploits

CVE-2026-42208 Pre-Auth SQL Injection via Authorization Header

Deterministic critical LiteLLM CISA KEV Added cve-verified-cve-2026-42208

Detects LiteLLM proxy instances 1.81.16-1.83.6 where the API-key lookup query interpolates the caller-supplied Authorization header directly into SQL via an f-string. When initial auth fails, the failure-logging callback runs the same f-stringed query against the raw Bearer token, so any unauthenticated request can inject SQL and read upstream provider keys (OpenAI/Anthropic/Bedrock/Vertex), virtual API keys, the proxy master key, and the runtime configuration. CISA added it to KEV within weeks of disclosure; in-the-wild exploitation began within 36 hours of the patch. The fix in 1.83.7 replaces the f-string with a $1 bind parameter and passes the hashed token as a positional arg.

Is your app exploitable through CVE-2026-42208?

Scan your domain free