
Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection
A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows attackers to bypass authentication mechanisms under specific conditions by exploiting improper handling of the Host header. The issue affects LiteLLM versions before 1.84.0 and has been assigned a […]
The post Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection appeared first on Cyber Security News.