Skip to content

docs: correct LiteLLM version guidance (CVE-2026-42208) - #95

Closed
sebastianomarchesini wants to merge 1 commit into
SAP-docs:mainfrom
sebastianomarchesini:patch-1
Closed

sebastianomarchesini wants to merge 1 commit into
SAP-docs:mainfrom
sebastianomarchesini:patch-1

Conversation

@sebastianomarchesini

Copy link
Copy Markdown

The caution note stated that LiteLLM 1.82.6 and below are safe to install. 1.82.6 falls inside the affected range of CVE-2026-42208 (>= 1.81.16, < 1.83.7), a critical SQL injection in the LiteLLM proxy, so the page recommended a vulnerable release.

Also clarified that 1.82.7 and 1.82.8 were a supply chain compromise rather than ordinary vulnerabilities, and added the remediation that requires: rotating credentials reachable from that environment and removing any litellm_init.pth file.

The replacement text sets a floor of 1.83.7 and points to the current release rather than naming a single safe version.

Refs: GHSA-r75f-5x8p-qvmc
Refs: https://docs.litellm.ai/blog/security-update-march-2026

Updated caution note regarding LiteLLM versions due to vulnerabilities and provided guidance on safe versions.
Reference 1: GHSA-r75f-5x8p-qvmc
Reference 2: https://docs.litellm.ai/blog/security-update-march-2026
@cla-assistant

cla-assistant Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@karu-0711 karu-0711 added contribution Valuable Contribution type/clarity Something was unclear in the documentation. follow-up-with/dev Clarification with development needed. labels Sep 17, 2026
@karu-0711

Copy link
Copy Markdown
Contributor

Thanks for your input. The documentation has now been updated.

@karu-0711 karu-0711 closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution Valuable Contribution follow-up-with/dev Clarification with development needed. type/clarity Something was unclear in the documentation.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants