CVE-2026-59822: BerriAI LiteLLM
BerriAI LiteLLMには、MCP Streamable HTTP エンドポイントの不正な認証脆弱性が含まれているため、未認証の攻撃者が任意のベアラートークンを使用して認証された MCP セッションを確立できます。
CISA (English)
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
- ベンダー
- BerriAI
- 製品
- LiteLLM
- 脆弱性
- BerriAI LiteLLM Improper Authentication Vulnerability
- 追加日
- 2026/09/02
- CISA対応期限(米国連邦機関向け)
- 2026/09/16
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-287, CWE-306
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02