Microsoft database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter Vulnerability
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs
What Happened
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs
Why This Matters
Publisher reporting describes a security event affecting may. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether may is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
May 11, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: ACTIVELY_EXPLOITED
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2026-42208: 6 public repository references found.
Possible public PoC reference
GitHub repository for an AI tooling project
0 stars ยท Shell
Open repositoryPublic exploit-related repository
Threat intelligence brief on CVE-2026-42208, a critical pre-auth SQL injection in BerriAI LiteLLM exploited within 36 hours of disclosure. Covers attack path, detection opportunities, and recommended actions.
0 stars
Open repositoryPublic GitHub reference
CVE-2026-42208 lab
0 stars ยท Python
Open repositoryPublic GitHub reference
GitHub repository for an AI tooling project
0 stars ยท Python
Open repositoryPublic GitHub reference
Scanner: CVE-2026-42208 LiteLLM SQL Injection โ Python scanner for BerriAI LiteLLM proxy instances
0 stars ยท Python
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
May 11, 2026 12:30BugSkan first recorded this incident.
-
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog - Security Affairs
May 11, 2026 12:30news.google.com ยท Data Leak
Sources
news.google.com ยท May 11, 2026 12:30
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Security Affairs
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.