CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy
bishopfox.com | vulnerability | Critical | Actively exploited | CVE-2026-42208 | #active-exploitation | #ai-security | #vulnerability-research | #sql-injection | #pre-auth | #litellm | #cve-2026-42208 | #ai-gateway
Summary
CVE-2026-42208 is a pre-auth SQL injection in LiteLLM proxy 1.81.16–1.83.6: a missing bind lets attackers run SQL on any LLM route, confirmed via pg_sleep timing; exploitation hit ~36 hours later.
- CVSS
- 9.8
- Published
- Collected
Skip to content