Server-side Request Forgery (SSRF) Affecting litellm package, versions [,1.88.6)[1.89.0rc1,1.89.7)[1.90.0rc1,1.90.7)[1.91.0rc1,1.91.5)[1.92.0rc1,1.92.2)[1.93.0rc1,1.93.2)[1.94.0rc1,1.94.3)[1.95.0rc1,1.95.1)[1.96.0rc1,1.96.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.31% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-LITELLM-19644158
  • published8 Sept 2026
  • disclosed2 Sept 2026
  • creditUnknown

Introduced: 2 Sep 2026

NewCVE-2026-84377  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade litellm to version 1.88.6, 1.89.7, 1.90.7, 1.91.5, 1.92.2, 1.93.2, 1.94.3, 1.95.1, 1.96.2 or higher.

Overview

litellm is a Library to easily interface with LLM API providers

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through request-body validation in the proxy auth path. An authenticated user can supply routing or credential parameters such as api_base, base_url, or other deployment-owned fields in the request body to redirect an outbound provider call to an attacker-controlled destination and make the proxy send its configured upstream credentials there. The vulnerable validation missed sensitive parameters and did not consistently inspect nested request fields, so caller-controlled body data could override server-side deployment settings instead of being rejected. From the user’s perspective, this can leak provider API keys and other configured secrets and can also be used to make the proxy reach internal services that are otherwise only accessible from its network.

CVSS Base Scores

version 4.0
version 3.1