LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
Summary
Hide ▲
Show ▼
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The update covers the disclosed flaws in the LiteLLM proxy and is the release users are told to deploy to close the risk. Systems on earlier builds remain exposed until they move to v1.83.14-stable or later.
Related Happenings
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch Release
H score55
First: 27.05.2026 13:06
Last: 27.05.2026 13:06
Sources 1
About this happening:
LiteSpeed released **urgent security updates** for the **cPanel user-end plugin** after **CVE-2026-48172** was found to be **actively exploited**, reducing exposure for systems ru...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch ReleaseAbout this happening: LiteSpeed released **urgent security updates** for the **cPanel user-end plugin** after **CVE-2026-48172** was found to be **actively exploited**, reducing exposure for systems ru...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score49
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
**Major Linux distributions** are rolling out fixes for **Dirty Frag**, the **Linux kernel** patch release that covers **CVE-2026-43284** and **CVE-2026-43500**. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: **Major Linux distributions** are rolling out fixes for **Dirty Frag**, the **Linux kernel** patch release that covers **CVE-2026-43284** and **CVE-2026-43500**. The update matter...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch Release
H score53
First: 30.04.2026 16:54
Last: 30.04.2026 16:54
Sources 1
About this happening:
**Linux kernel** maintainers have fixed **CVE-2026-31431** and are rolling out updates to close a **local privilege escalation** flaw that lets an unprivileged attacker gain **roo...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch ReleaseAbout this happening: **Linux kernel** maintainers have fixed **CVE-2026-31431** and are rolling out updates to close a **local privilege escalation** flaw that lets an unprivileged attacker gain **roo...
DELMIA Apriso patch release for CVE-2025-6204 and CVE-2025-6205
Security Patch Release
H score52
First: 29.10.2025 10:24
Last: 29.10.2025 10:24
Sources 1
About this happening:
**Dassault Systèmes** released **patches and barebone advisories** for **DELMIA Apriso** vulnerabilities **CVE-2025-6204** and **CVE-2025-6205**, covering releases **2020 through...
DELMIA Apriso patch release for CVE-2025-6204 and CVE-2025-6205
Security Patch ReleaseAbout this happening: **Dassault Systèmes** released **patches and barebone advisories** for **DELMIA Apriso** vulnerabilities **CVE-2025-6204** and **CVE-2025-6205**, covering releases **2020 through...
Timeline
-
15.06.2026 19:39 2 articles · 2h ago
BerriAI ships LiteLLM v1.83.14-stable to close a three-CVE chain
Mitigation Patch UpdateBerriAI released LiteLLM v1.83.14-stable with the complete fix set for CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217, closing the route-gate bypass, privilege escalation, and sandbox escape path for LiteLLM proxy deployments.
Show sources
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39
-
15.06.2026 19:39 1 articles · 2h ago
Obsidian Security discloses a LiteLLM proxy takeover chain
Initial DisclosureObsidian Security publicly disclosed a three-vulnerability chain in LiteLLM that can let a default low-privilege internal_user reach proxy_admin and run code on the server, with a full-chain CVSS rating of 9.9 and a recommendation to upgrade to v1.83.14-stable or later.
Show sources
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers — thehackernews.com — 15.06.2026 19:39