LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
GHSA-hx8v-g79f-8w5f · CVE-2026-59823
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the
proxy's outbound request to a host of their choosing by smuggling an api_base inside theuser_config request body, bypassing the existing parameter guard.
Details
LiteLLM Proxy validates request bodies with is_request_body_safe, which blocks theapi_base and base_url parameters but does not cover user_config. The user_config
object is used to build the outbound router for a request, so a caller can place anapi_base inside it and reach an arbitrary host. The guard only inspected the two
top-level keys, so the same api_base nested inside user_config was never checked.
Exploitation requires a valid virtual key.
Impact
An authenticated caller can make the proxy issue server-side requests to internal or
external hosts of their choosing, reaching endpoints the caller cannot otherwise access.
Affected / Patched
Affected: <= 1.83.8
Patched: 1.83.9
Remediation
Upgrade to 1.83.9 or later (released 2026-04-17).
References
- WEB https://github.com/BerriAI/litellm/security/advisories/GHSA-hx8v-g79f-8w5f
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-59823
- WEB https://github.com/BerriAI/litellm/pull/25827
- WEB https://github.com/BerriAI/litellm/commit/47214be317f45a2d2ac08258362e0481411eb427
- PACKAGE https://github.com/BerriAI/litellm
Ready to move
Start Securing
Free, no credit card | First findings in minutes