Threat · curated 28 Jul 2026
CVE-2026-49468 - Red Hat Customer Portal
First reported redhat.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
LiteLLM is a widely deployed AI gateway fronting LLM APIs, so an unauthenticated Host-header auth bypass exposing management routes gives attackers a direct path to compromise AI infrastructure and the models and keys behind it.
CVE-2026-49468 is an Important-severity (CVSS 8.1) authentication-bypass flaw in LiteLLM, a proxy server (AI Gateway) used to call LLM APIs. A remote attacker sending a crafted Host header can bypass the proxy authentication layer to gain unauthenticated access to protected management routes, potentially leading to full system compromise. The issue is fixed in LiteLLM v1.84.0 (GHSA-4xpc-pv4p-pm3w), and Red Hat notes its default images do not start the vulnerable proxy.