External risk intelligence

LiteLLM MCP Endpoint Improper Authentication Vulnerability

CVE advisoryKnown Exploit

CVE-2026-59822

LiteLLM is designed as an AI gateway proxy, which is a component commonly deployed as a public-facing API endpoint to interface between internet-based clients and various LLM service providers. Its primary function is to handle network requests, making this interface a core, internet-exposed component by design.

Authentication Bypass

Litellm

before 1.84.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in LiteLLM, an AI gateway proxy, that could allow unauthenticated access to its MCP tooling. This occurs when a crafted authorization header bypasses key validation, potentially exposing sensitive operations. The main concern is to confirm if this technology is in use and if it is exposed externally.

  • Unauthorized access to AI gateway tooling.
  • Affects systems acting as AI proxies.
  • Confirm relevance and external exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the LiteLLM proxy server's MCP Streamable HTTP endpoint. This request would manipulate the Authorization header to bypass LiteLLM's key validation, allowing it to proceed without a proper key. This could enable unauthorized access to internal tooling.

  • Unauthenticated network access required.
  • Fabricated Authorization header triggers fallback.
  • Unauthorized access to internal tooling.

Live Threat

Current exploitation, exposure, and threat context

LiteLLM's MCP Streamable HTTP endpoint, when improperly configured, could allow unauthenticated requests to bypass authentication checks and reach its internal tooling. This could occur when the system fails to properly validate a LiteLLM API key, enabling an attacker to send a fabricated Authorization header to trigger an OAuth2 passthrough, thereby replacing the necessary key validation with an empty object.

  • Unauthorized access to tooling.
  • Malicious headers bypass authentication.
  • Compromised service integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The LiteLLM proxy server, specifically its MCP Streamable HTTP endpoint, is susceptible to unauthenticated access due to a flaw in its OAuth2 passthrough. Teams responsible for AI infrastructure, API gateways, or applications leveraging LLMs should prioritize identifying all instances of LiteLLM. Confirming their exposure, business criticality, and the accountable owner is the crucial first step before planning remediation.

  • Application or platform owners should address this.
  • Verify LiteLLM instances and their reachability.
  • Plan updates based on risk and operational needs.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LiteLLM?

LiteLLM is an open-source AI gateway proxy used by developers to standardize how applications connect to various Large Language Model (LLM) APIs. It acts as a middleware layer, allowing systems to call different AI models using a unified format. By sitting between your applications and LLM providers, it simplifies tasks like key management, load balancing, and logging for complex AI-driven workflows.

What does CWE-287 mean for CVE-2026-59822?

This CVE involves Improper Authentication (CWE-287) and Missing Authentication for Critical Function (CWE-306). Essentially, the software fails to verify who is making a request. In this specific case, LiteLLM contains a logic flaw where an invalid request can trick the system into skipping its security checks entirely, allowing unauthorized users to interact with protected Model Context Protocol (MCP) tooling as if they were legitimate, authorized users.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a network request to the MCP Streamable HTTP endpoint containing a specifically fabricated Authorization header. This crafted header forces the system into an unintended OAuth2 fallback process, which replaces legitimate key validation with an empty object. Requests that do not use this specific fabricated header structure, or that are directed at other LiteLLM endpoints not associated with the MCP feature, do not trigger this bypass.

Is my LiteLLM instance vulnerable?

According to Halo Surface Signal, LiteLLM is often deployed as a public-facing API gateway specifically to handle traffic between the internet and LLM providers, making it a highly likely candidate for external exposure. If your LiteLLM proxy is reachable from the public internet, it should be considered at risk. Internal-only instances are also susceptible, but their reachability is restricted to users within your private network.

What should I do to address this issue?

The primary step is to identify all running instances of LiteLLM in your environment to determine if they are version 1.84.0 or older. Once you have an inventory, prioritize upgrading any affected instances to version 1.84.0 or later, as this version contains the necessary fix. If an immediate update is not possible, evaluate if you can restrict network access to the MCP endpoint to only trusted sources until the update is applied.

References