Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12795

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 7.3

Описание

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

A flaw was found in BerriAI litellm. This vulnerability allows a remote attacker to bypass authentication within the SSO Debug Flow component by manipulating the json.dumps function. The successful exploitation of this flaw could lead to unauthorized access and potential information disclosure.

Отчет

This Important vulnerability in BerriAI litellm's SSO Debug Flow allows remote unauthenticated access. However, Red Hat products, including Red Hat OpenShift AI, are not affected by this flaw as the vulnerable code is either not present or not in an executable path within these offerings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2491137litellm: BerriAI litellm: Missing authentication in SSO Debug Flow allows remote access.

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
около 2 месяцев назад

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

CVSS3: 7.3
github
около 2 месяцев назад

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

7.3 High

CVSS3