8 views
-/https://github.com/berriai/litellm/issues/33405
GitHub · issue

#33405 Upgrade gunicorn to 26 for proxy security fix

  • State: open
  • Author: @mielverkerken

LiteLLM proxy currently allows `gunicorn>=23.0.0,<24.0` through the proxy extra

The Aikido advisory `AIKIDO-2026-10742` reports `gunicorn` versions `0.1` through `25.3.0` as affected by HTTP request smuggling and related HTTP framing issues, with `26.0.0` as the fixed release

The proxy dependency should move to `gunicorn>=26.0.0,<27.0`, and the lockfile should resolve `gunicorn==26.0.0`, so proxy installs no longer resolve a vulnerable `gunicorn` release

https://intel.aikido.dev/cve/AIKIDO-2026-10742

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (5 events)
#0 of 0 · 31d18h59m22s ago — entered · #import:https:::github.com:berriai:litellm post #1873
28642 requires tracing persistence, ORM/model serialization, API response schemas, and regression coverage across proxy and UI flows, with compatibility risk. 33405 is primarily a constrained dependency and lockfile update with focused validation.
The left issue requires tracing and correcting runtime authorization, spend accounting, customer identity, and per-model budget interactions, with regression coverage across request paths. The right is a constrained dependency and lockfile update with focused compatibility verification.
The left requires coordinated changes across runtime behavior, configuration, and performance-sensitive paths, creating broader regression risk and testing scope. The right is a contained dependency and lockfile maintenance change.
#34101 requires coordinated changes across reservation, persistence, reseeding, request plumbing, concurrency behavior, and regression tests; #33405 is primarily a dependency and lockfile update with focused validation.
#0 of 0 · 31d17h49m22s ago — current · #import:https:::github.com:berriai:litellm post #3045
#33327 requires correcting control flow in budget filtering, validating interactions with multiple budget types, and adding regression coverage; #33405 is primarily a constrained dependency and lockfile update with focused compatibility checks.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search