---
schema: 1
kind: vulnerability
title: "CVE-2026-42208 — LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk"
headline: "CVE-2026-42208 — LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk"
summary: "LiteLLM Proxy pre-auth SQL injection (CVE-2026-42208) added to CISA KEV on 2026-05-08, deadline 2026-05-11. The proxy holds all upstream LLM-provider API keys (OpenAI, Anthropic, Azure, etc.) in its database; a blind time-based injection via the Authorization: Bearer header yields full read/write access to credential tables."
discovered_at: "2026-05-09T05:00:04Z"
event_date: 2026-04-30
run_id: 2026-05-09-migrated
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - auth-bypass
  - cisa-kev
  - patch-available
  - cloud
  - ai-abuse
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-42208
    cvss: "9.3"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy"
    publisher: "Bishop Fox — CVE-2026-42208 technical analysis, 2026-04-30"
    role: primary
  - url: "https://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection"
    publisher: "LiteLLM vendor advisory, 2026-04-29"
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-42208 (CWE-89, CVSS 9.3) is a pre-authentication f-string SQL injection in the PrismaClient.get_data() method of LiteLLM Proxy, an open-source AI API gateway that centralises access management for upstream LLM provider keys (OpenAI, Anthropic, Azure OpenAI, Cohere, etc.)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-09.md
---

CVE-2026-42208 (CWE-89, CVSS 9.3) is a pre-authentication f-string SQL injection in the `PrismaClient.get_data()` method of LiteLLM Proxy, an open-source AI API gateway that centralises access management for upstream LLM provider keys (OpenAI, Anthropic, Azure OpenAI, Cohere, etc.). The caller-supplied `Authorization: Bearer <token>` value is interpolated directly into a PostgreSQL query string rather than passed as a parameterised argument. An unauthenticated attacker sends a crafted token to any LLM API route (e.g., `POST /v1/chat/completions`) and performs blind time-based injection via `pg_sleep()`, targeting `LiteLLM_VerificationToken`, `litellm_credentials`, and `litellm_config` tables — which collectively hold every virtual API key, upstream provider credential, team binding, and rate-limit configuration in the proxy ([Bishop Fox, 2026-04-30](https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy) · [LiteLLM vendor advisory, 2026-04-29](https://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection)). On default deployments where the application database user holds superuser rights, an attacker gains full read/write access to the database. In-the-wild exploitation began within approximately 26–36 hours of the GitHub Security Advisory (GHSA-r75f-5x8p-qvmc) publication. CISA added the CVE to KEV on 2026-05-08 with a federal remediation deadline of **2026-05-11**. Fixed in LiteLLM v1.83.7+. Patching does not remediate credential compromise on instances that were already exposed; operators should rotate all upstream API keys stored in the proxy database.
