1.
bishopfox.com | vulnerability | Critical | [Actively exploited] | | original ↗ | #active-exploitation | #ai-security | #vulnerability-research | #sql-injection
CVE-2026-42208 is a pre-auth SQL injection in LiteLLM proxy 1.81.16–1.83.6: a missing bind lets attackers run SQL on any LLM route, confirmed via pg_sleep timing; exploitation hit ~36 hours later.
Skip to content