LiteLLM MCP endpoint authentication bypass via forged Authorization header (CVE-2026-59822)
Prior to version 1.84.0, LiteLLM's MCP Streamable HTTP endpoint let an unauthenticated attacker send a fabricated Authorization header that triggered an OAuth2 passthrough fallback, substituting an empty UserAPIKeyAuth() object for failed key validation and granting access to MCP tooling without a valid LiteLLM key. The issue was fixed in release 1.84.0.
Disclosed 8 July 2026 · Record updated 13 September 2026
Impact
Unauthenticated requests could reach MCP tooling through the LiteLLM AI gateway without a valid API key.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59822
