IC Technology & Surveillance — 2026-05-11

CISA Adds BerriAI LiteLLM Flaw to Known Exploited Vulnerabilities Catalog

CISA added CVE-2026-42208, a SQL injection flaw in BerriAI's LiteLLM AI proxy, to its Known Exploited Vulnerabilities catalog on May 8. The vulnerability resides in the proxy's API key verification path and allows unauthenticated remote access to database contents via a crafted Authorization header; Security Affairs and Windows News AI report diverging CVSS scores of 9.3 and 9.8, respectively. Sysdig's Threat Research Team observed the first exploitation attempt 36 hours after public disclosure, describing deliberate schema enumeration targeting virtual API key, stored provider credential, and environment-variable tables, with no confirmed exfiltration or follow-on credential abuse. BerriAI patched the flaw in version 1.83.7 on April 19; sources report conflicting FCEB remediation deadlines of May 11 (Security Affairs) and June 5 (Windows News AI).

Analysis
The deliberate schema enumeration Sysdig observed, targeting LiteLLM's credential and key tables 36 hours after disclosure, points to an actor who had mapped the application before the advisory went public, not opportunistic scanning. Halting without confirmed exfiltration does not demonstrate the actor lacked read access; automated tooling completing a pre-programmed phase is equally viable. LiteLLM aggregates credentials for every LLM provider an organization runs, making its KEV listing a meaningful expansion of CISA's tracked federal attack surface. Conflicting remediation deadlines, May 11 versus June 5, with Windows News AI's figures unverifiable against both CISA and Security Affairs, leave genuine compliance ambiguity. Whether at least one FCEB agency is found non-compliant within 90 days is genuinely uncertain at moderate confidence.
1 sources
  1. U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE