⤷ Title: LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 01:35:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #API security #Authentication Bypass #CVE_2026_49468 #CWE_290 #FastAPI #host header injection #LiteLLM #LLM Proxy #Starlette
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 01:35:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #API security #Authentication Bypass #CVE_2026_49468 #CWE_290 #FastAPI #host header injection #LiteLLM #LLM Proxy #Starlette
Daily CyberSecurity
LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
A critical LiteLLM authentication bypass (CVE-2026-49468) lets crafted Host Header Injection reach protected AI Gateway routes. Patch in 1.84.0.