Threat

NVD-CVE-2026-59823

Page published

Publication date unknown · First observed: 7 Oct 2026

Coverage timeline

7 Oct 2026nist.govobserved

Single-source advisory — one report is available.

Why it matters

CVE-2026-59823 lets an authenticated caller turn a widely deployed LLM proxy into an SSRF pivot into internal networks, so defenders running LiteLLM gateways should upgrade to 1.83.9.

CVE-2026-59823 is an SSRF vulnerability in LiteLLM, an AI gateway proxy for LLM APIs, affecting versions prior to 1.83.9. An authenticated caller with a valid virtual key can place api_base inside the user_config request body to bypass is_request_body_safe checks, which only blocked top-level api_base/base_url, allowing the outbound router to redirect server-side requests to attacker-chosen internal or external hosts and expose otherwise inaccessible endpoints. The issue is fixed in version 1.83.9.