Threat · curated 28 Jul 2026

CVE-2026-49468 - Red Hat Customer Portal

Coverage timeline

28 Jul 2026redhat.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

LiteLLM is a widely deployed AI gateway fronting LLM APIs, so an unauthenticated Host-header auth bypass exposing management routes gives attackers a direct path to compromise AI infrastructure and the models and keys behind it.

CVE-2026-49468 is an Important-severity (CVSS 8.1) authentication-bypass flaw in LiteLLM, a proxy server (AI Gateway) used to call LLM APIs. A remote attacker sending a crafted Host header can bypass the proxy authentication layer to gain unauthenticated access to protected management routes, potentially leading to full system compromise. The issue is fixed in LiteLLM v1.84.0 (GHSA-4xpc-pv4p-pm3w), and Red Hat notes its default images do not start the vulnerable proxy.