CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-108574: LiteLLM 1.0, 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19…

CVE-2026-108574. CVSS 2.0 base score 4.0 (MEDIUM, Vendor/CNA).

Affected technology

LiteLLM · 1.0, 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.30, 1.31, 1.32, 1.33, 1.34, 1.35, 1.36, 1.37, 1.38, 1.39, 1.40, 1.41, 1.42, 1.43, 1.44, 1.45, 1.46, 1.47, 1.48, 1.49, 1.50, 1.51, 1.52, 1.53, 1.54, 1.55, 1.56, 1.57, 1.58, 1.59, 1.60, 1.61, 1.62, 1.63, 1.64, 1.65, 1.66, 1.67, 1.68, 1.69, 1.70, 1.71, 1.72, 1.73, 1.74, 1.75, 1.76, 1.77, 1.78, 1.79, 1.80, 1.81, 1.82, 1.83, 1.84, 1.85, 1.86, 1.87, 1.88, 1.89, 1.90, 1.91, 1.92, 1.93, 1.94, 1.95.0
BerriAI

Description’s affected range: up to 1.95.0

Component: Spend Tracking
Function: ui_view_session_spend_logs
File: litellm/proxy/spend_tracking/spend_management_endpoints.py

Attack conditions (VulDB, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment (base score 2.1/10) rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-285, CWE-639
CCR priority
16.0 /100 (P5)
CVSS 2.0
4.0 /10 · CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:N/A:N · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108574.html