LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
Summary
Hide ▲
Show ▼
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The update covers the disclosed flaws in the LiteLLM proxy and is the release users are told to deploy to close the risk. Systems on earlier builds remain exposed until they move to v1.83.14-stable or later.
Related Happenings
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Squid web proxy patch for CVE-2026-47729
Security Patch Release
H score20
First: 22.06.2026 17:29
Last: 22.06.2026 17:29
Sources 1
About this happening:
Squid maintainers merged a null-terminator check for CVE-2026-47729 into the development branch and v7, closing the FTP-parser over-read that could expose shar...
Squid web proxy patch for CVE-2026-47729
Security Patch ReleaseAbout this happening: Squid maintainers merged a null-terminator check for CVE-2026-47729 into the development branch and v7, closing the FTP-parser over-read that could expose shar...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch Release
H score46
First: 17.06.2026 13:09
Last: 17.06.2026 13:09
Sources 1
About this happening:
JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch ReleaseAbout this happening: JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
H score38
First: 16.06.2026 08:41
Last: 16.06.2026 08:41
Sources 1
About this happening:
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/MitigationAbout this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch Release
H score42
First: 27.05.2026 13:06
Last: 27.05.2026 13:06
Sources 1
About this happening:
LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch ReleaseAbout this happening: LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
Latest development: 16.06.2026 13:47
CISA added CVE-2026-48172/CVE-2026-54420 in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers within three days under BOD 26-04. The affected plugin versions before 2.4.8 are described as actively exploited, with FTP or web shell access enabling root escalation on shared hosting servers running CloudLinux/CageFS.
Timeline
-
15.06.2026 19:39 2 articles · 1mo ago
BerriAI ships LiteLLM v1.83.14-stable to close a three-CVE chain
Mitigation Patch UpdateBerriAI released LiteLLM v1.83.14-stable with the complete fix set for CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217, closing the route-gate bypass, privilege escalation, and sandbox escape path for LiteLLM proxy deployments.
Show sources
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39
-
15.06.2026 19:39 1 articles · 1mo ago
Obsidian Security discloses a LiteLLM proxy takeover chain
Initial DisclosureObsidian Security publicly disclosed a three-vulnerability chain in LiteLLM that can let a default low-privilege internal_user reach proxy_admin and run code on the server, with a full-chain CVSS rating of 9.9 and a recommendation to upgrade to v1.83.14-stable or later.
Show sources
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39