Database/AI/ML frameworks & serving

LiteLLM proxy: Two endpoints allow privilege escalation / unauthorized action
CVSS 8.8CVE-2026-42271AI/ML frameworks & servingKnown exploitedcurated
Impact
Two endpoints allow privilege escalation / unauthorized action
Who can reach it
Authenticated low-privilege proxy user
What to do
**[KEV]** Patch to 1.83.7+ immediately
References
Related entries
- LiteLLM proxy: SQL injection in a database query pathCVE-2026-42208 · LiteLLM proxyCritical
- LiteLLM proxy: Host-header parsing flaw in the proxyCVE-2026-49468 · LiteLLM proxyCritical
- BentoML (`bentofile.yaml`): Malicious build manifestCVE-2026-44346 · BentoML (`bentofile.yaml`)High
- ChromaDB (SimpleRBAC): Authorization provider evaluates permissions incorrectlyCVE-2026-45831 · ChromaDB (SimpleRBAC)High
- ChromaDB (V1 endpoints): Tenant/database passed as `None` to the authz layerCVE-2026-45832 · ChromaDB (V1 endpoints)High
- ChromaDB: Authenticated code injectionCVE-2026-45833 · ChromaDBHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.