LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 8, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 11, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-42208 to its Known Exploited Vulnerabilities catalog on May 8, 2026, with a federal patch deadline of May 11, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the…

BerriAI LiteLLM contains a SQL injection vulnerability tracked as CVE-2026-42208. The flaw allows an attacker to read data from the proxy's database and potentially modify it, which can result in unauthorized access to the proxy itself and to the credentials it manages.

How it works

The weakness is categorized as CWE-89, SQL injection. An attacker supplies crafted input that alters the structure of database queries executed by the LiteLLM proxy. Successful exploitation can expose stored data or permit changes to records, directly affecting the proxy's configuration and any credentials held in its database.

Am I affected? How to find it in your systems

Inventory all deployments of BerriAI LiteLLM, including containerized instances, cloud-hosted proxies, and any environments where it fronts LLM API calls. Confirm the presence and configuration of the database component referenced in the CISA summary. Review database query logs and proxy access logs for anomalous patterns such as unexpected input strings or queries that deviate from expected application behavior. Specific version and configuration details must be checked against the vendor advisory.

How to remediate

Apply mitigations per the vendor instructions. Follow applicable BOD 22-01 guidance for cloud services. Where mitigations are unavailable, discontinue use of the product. After applying updates, validate that the database interaction paths no longer accept unsanitized input from untrusted sources.

If you can't patch immediately

Restrict network access to the LiteLLM proxy so that only trusted clients can reach it. Monitor database and proxy logs for signs of unexpected query structure or data access. Consider disabling features that expose the affected database paths until remediation is complete. If the instance runs in a cloud environment, apply the relevant BOD 22-01 controls.

If your data may have been exposed

Actively exploited vulnerabilities of this class have led to breaches involving credential and configuration data. Organizations can run a free exposure scan of their email domains to check for presence in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBerriAI · LiteLLM
WeaknessCWE-89
Added to CISA KEVMay 8, 2026
Federal patch deadlineMay 11, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities