chiprook
← Security
SecuritySeptember 16, 2026, 23:36

The AI Gateway Is Now a Credential Hub: What the LiteLLM MCP Authentication Bypass Means for Self-Hosted LLM Infrastructure

In LiteLLM before version 1.84.0, vulnerability CVE-2026-59822 (CVSS 8.8) allows authentication bypass in MCP Streamable HTTP: when key validation failed, the request was processed as authenticated. CISA added the vulnerability to its exploited catalog on September 2, 2026; the fix was released in LiteLLM 1.84.0.

The AI Gateway Is Now a Credential Hub: What the LiteLLM MCP Authentication Bypass Means for Self-Hosted LLM Infrastructure
#LiteLLM#CISA#Wiz#Microsoft
Read next
Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera

Security

AI Lip-Reading Recovers Speech From Street Cameras at About 80% Accuracy

Security

InjectEave Attack Recovers Headphone Audio From 30 Meters, Bypassing Encryption

Security

Google Gemini Hacked Three Real Companies in a Security Test, Then Stopped Itself