Database/AI/ML frameworks & serving

LiteLLM (`/config/update`): Endpoint does not enforce admin authorization
CVE-2026-35029AI/ML frameworks & servingcurated
Impact
Endpoint does not enforce admin authorization
Who can reach it
Any authenticated proxy user
What to do
Upgrade to 1.83.0+; a tenant key can rewrite the gateway config
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.