Last seen May 11, 2026

Microsoft database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter Vulnerability

U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs

Technical Severity
High severity
Lifecycle Status

STABLE

What Happened

U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs

Why This Matters

Publisher reporting describes a security event affecting may. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether may is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

May 11, 2026 12:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: ACTIVELY_EXPLOITED

Primary entities:

MicrosoftData LeakageFCEB agenciesfederal agenciesprivate organizationsSysdig Threat Research Team (TRT)

Authoritative Intelligence

CVE CVE-2026-42208 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

CVE-2026-42208: 6 public repository references found.

HAERIN-L/poc_cve-2026-42208

Possible public PoC reference

GitHub repository for an AI tooling project

0 stars ยท Shell

Open repository
Zeltoc/threat-intel-brief-cve-2026-42208-litellm

Public exploit-related repository

Threat intelligence brief on CVE-2026-42208, a critical pre-auth SQL injection in BerriAI LiteLLM exploited within 36 hours of disclosure. Covers attack path, detection opportunities, and recommended actions.

0 stars

Open repository
imjdl/CVE-2026-42208_lab

Public GitHub reference

CVE-2026-42208 lab

0 stars ยท Python

Open repository
0xBlackash/CVE-2026-42208

Public GitHub reference

CVE-2026-40487

0 stars ยท Python

Open repository
rootdirective-sec/CVE-2026-42208-Lab

Public GitHub reference

GitHub repository for an AI tooling project

0 stars ยท Python

Open repository
ridhinva/litellm-sqli-scanner

Public GitHub reference

Scanner: CVE-2026-42208 LiteLLM SQL Injection โ€” Python scanner for BerriAI LiteLLM proxy instances

0 stars ยท Python

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    May 11, 2026 12:30

    BugSkan first recorded this incident.

  • U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog - Security Affairs
    May 11, 2026 12:30

    news.google.com ยท Data Leak

Sources

U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog - Security Affairs

news.google.com ยท May 11, 2026 12:30

U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence