9 views
-/https://github.com/berriai/litellm/issues/35541
GitHub · issue

#35541 [Bug]: Security vulnerabilities 1.94.0: CVE-2026-12772 CVE-2026-12795 CVE-2026-12796

  • State: open
  • Author: @qdrddr
  • Labels: bug, SDK

### Check for existing issues

- [x] I have searched the existing issues and checked that my issue is not a duplicate.

### What happened?

[Snyk reports litellm](https://security.snyk.io/package/pip/litellm) 1.94.X/1.95.X/1.96.X all contain three known security vulnerabilities with publicly assigned CVEs. All three issues are direct dependencies and currently have no supported remediation path because no patched LiteLLM release is available.

Affected vulnerabilities:

CVE-2026-12772 – Insufficient Session Expiration (CWE-613), CVSS 7.1 CVE-2026-12795 – Missing Authentication for Critical Function (CWE-306), CVSS 6.9 CVE-2026-12796 – Insufficient Session Expiration (CWE-613), CVSS 5.3 CVE-2024-6825 - reported by fossa.com

Snyk reports that all three vulnerabilities have Proof-of-Concept exploits available and that there is currently no supported fix.

### What did you expect to happen? The project should use a version of LiteLLM that does not contain these known security vulnerabilities, or update the dependency once an upstream release containing fixes becomes available. If an upgrade is not yet possible, documenting the impact and any recommended mitigations would also be helpf…

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (2 events)
#0 of 0 · 31d17h58m22s ago — entered · #import:https:::github.com:berriai:litellm post #2897
The security work is harder because it requires vulnerability triage, dependency and upstream-fix coordination, compatibility validation, and potentially broader mitigation or release work. The credential-form issue is more localized to provider-specific UI configuration and validation, with a narrower test surface.
#0 of 0 · 31d17h57m40s ago — current · #import:https:::github.com:berriai:litellm post #2909
Resolving multiple high-severity dependency vulnerabilities without breaking compatibility may require coordinated upstream upgrades, validation, mitigation design, and security release management. The authentication defect is more localized: correcting session-policy handling with focused AWS integration tests.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search