Knox CVE Database
/
CVE-2026-42208
Critical
9.8

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Added to the CISA KEV catalog:
May 8, 2026

Overview

LiteLLM, an AI gateway proxy that routes requests to large language model APIs, contains a SQL injection flaw in the code path that verifies API keys. Versions from 1.81.16 up to but not including 1.83.7 are affected. An unauthenticated attacker with network access to the proxy can read sensitive data from its backing database, including the LLM API credentials the proxy manages, and may be able to modify that data to gain unauthorized access to the proxy itself.

Vulnerability details

Affected vendor
BerriAI
Affected product
LiteLLM
Weakness type (CWE)
CWE-89

SQL injection (CWE-89) occurs when user-supplied input is concatenated directly into a query string rather than passed as a bound parameter. In LiteLLM, the proxy's API key verification routine takes the value from the caller's Authorization header and interpolates it into the query text. Because the database never receives the key as a separate, typed parameter, it cannot distinguish between a legitimate key value and attacker-supplied SQL syntax. The error-handling path that invokes this query is reachable on any LLM API route, meaning the injection point is exposed across the proxy's entire API surface.


An unauthenticated attacker sends a crafted HTTP request to any LLM API route, such as POST /chat/completions, with a malicious Authorization header value. The proxy's error-handling path processes the header through the vulnerable key-verification query, allowing the attacker to manipulate the SQL statement. A successful attack yields read access to the proxy's database contents, including stored LLM API credentials and other secrets. The attacker may also be able to modify database records, which could allow unauthorized access to the proxy and the downstream LLM services it manages.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor application and database logs for SQL syntax characters or keywords (single quotes, comment sequences, UNION, SELECT) appearing in Authorization header values on LiteLLM proxy API routes such as POST /chat/completions.
  • Audit database query logs for unexpected SELECT or UPDATE statements originating from the LiteLLM process that include inline string literals where a parameterized placeholder would normally appear, particularly during API key verification calls.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
May 11, 2026

Additional hardening

  • Upgrade LiteLLM to version 1.83.7 or later, which patches the vulnerable API key verification query by using parameterized statements instead of string concatenation.
  • Restrict network access to the LiteLLM proxy so that only authorized clients and services can reach its API routes; place it behind an API gateway or firewall that limits inbound connections to known sources.
  • Apply a web application firewall rule to inspect and block Authorization header values containing SQL metacharacters (single quotes, double dashes, semicolons, UNION, SELECT) before they reach the proxy.
  • Rotate all LLM API credentials and other secrets stored in the proxy's database immediately if the proxy ran an affected version while network-accessible, as those credentials should be treated as compromised.

Key dates

Published (NVD)
May 8, 2026
Added to CISA KEV
May 8, 2026
Remediation deadline
May 11, 2026
Last updated
July 14, 2026

References

Frequently asked questions

Does CVE-2026-42208 affect my FedRAMP authorization?

If BerriAI LiteLLM runs inside your authorization boundary, yes. CVE-2026-42208 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of May 11, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. You either remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-42208?

Knox does not patch your software. Remediating BerriAI LiteLLM is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that support your documentation for the next assessment. Applying the fix is yours to own; maintaining a compliant posture while you work through it is not something you have to manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-42208, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving you earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-42208's remediation deadline of May 11, 2026 has passed. What happens now?

An unremediated CVE-2026-42208 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing out the finding and formally documenting why the May 11, 2026 deadline was missed is what keeps your authorization clean and your agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.