PT-2026-30279 · Litellm · Litellm

Veria-Labs

·

Published

2026-04-03

·

Updated

2026-04-17

·

CVE-2026-35030

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions LiteLLM versions prior to 1.83.0
Description A critical authentication bypass can occur in LiteLLM when JWT authentication is enabled, due to an OIDC userinfo cache key collision. The OIDC userinfo cache uses the first 20 characters of the token as the cache key. JWT headers from the same signing algorithm produce identical first 20 characters, allowing an unauthenticated attacker to craft a token that matches a legitimate user's cached token. Upon a cache hit, the attacker can inherit the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled.
Recommendations Update to version 1.83.0 or later. Disable OIDC userinfo caching by setting the cache TTL to 0. Disable JWT authentication entirely.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-35030
ECHO-B229-8FDA-451C
GHSA-JJHC-V7C2-5HH6

Affected Products

Litellm