CVE-2026-59822: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Published Jul 8, 2026
·
Updated

Impact

LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key validation with an empty UserAPIKeyAuth() object. This allowed requests with a fabricated Authorization header to reach MCP tooling without a valid LiteLLM key.

An attacker could use this to list and call configured MCP tools and access connected services exposed through MCP.

Patches

The issue is fixed in 1.84.0.

We recommend upgrading to 1.84.0 or later.

Workarounds

If upgrading is not immediately possible, disable MCP routes or block access to /mcp/ and related MCP endpoints at your reverse proxy or API gateway.

References

v1.84.0

Other sources

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

MITRE

Affected Software

3 affected componentsFixes available
LiteLLM<1.84.0
LiteLLM LiteLLM<1.84.0
pip/litellm<1.84.0
1.84.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/litellm to a version that resolves this vulnerability.

    Fixed in 1.84.0
  2. Upgrade

    Upgrade litellm to a version that resolves this vulnerability.

    Fixed in 1.84.0
  3. Compensating control

    If upgrading is not immediately possible, disable MCP routes or block access to /mcp/ and related MCP endpoints at your reverse proxy or API gateway.

Event History

Jul 8, 2026
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Advisory Published
via GitHub·10:38 PM
Data Sourced
via GitHub·10:38 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59822?

The severity of CVE-2026-59822 is rated as high with a score of 8.8.

2

How do I fix CVE-2026-59822?

To fix CVE-2026-59822, upgrade LiteLLM to version 1.84.0 or later.

3

What type of vulnerability is CVE-2026-59822?

CVE-2026-59822 is an authentication bypass vulnerability via OAuth2 Passthrough Fallback.

4

Who is impacted by CVE-2026-59822?

Users of LiteLLM versions prior to 1.84.0 are impacted by CVE-2026-59822.

5

What can an attacker do with CVE-2026-59822?

An attacker can exploit CVE-2026-59822 to trigger unauthorized access to the LiteLLM API using a fabricated Authorization header.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203