Threat · curated 17 Jul 2026
NVD - CVE-2026-59819
First reported nist.gov
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
LiteLLM is widely deployed as an LLM gateway, and this file-read flaw lets a privileged proxy admin exfiltrate local filesystem contents such as secrets and credentials, so operators should upgrade to the patched release.
CVE-2026-59819 is a vulnerability in LiteLLM, an AI gateway/proxy for calling LLM APIs, where prior to version 1.83.10-stable the /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a privileged caller to read arbitrary local files via an oidc/file/ reference (CWE-73). The issue is fixed in version 1.83.10-stable.