CVE-2026-35030
LiteLLM JWT Authentication Cache Bypass Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in LiteLLM, an AI gateway, could allow an unauthenticated attacker to impersonate legitimate users by exploiting a JWT authentication cache mechanism. This affects deployments where JWT/OIDC authentication is specifically enabled, potentially leading to unauthorized access to user identities and permiss