Exploited Vulnerabilities Daily
🌐 日本語

← 新着一覧

CVE-2026-59822: BerriAI LiteLLM

BerriAI LiteLLMには、MCP Streamable HTTP エンドポイントの不正な認証脆弱性が含まれているため、未認証の攻撃者が任意のベアラートークンを使用して認証された MCP セッションを確立できます。

CISA (English)

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

ベンダー
BerriAI
製品
LiteLLM
脆弱性
BerriAI LiteLLM Improper Authentication Vulnerability
追加日
2026/09/02
CISA対応期限(米国連邦機関向け)
2026/09/16
ランサムウェア攻撃での利用
不明
弱点(CWE)
CWE-287, CWE-306

参考情報

当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。

最終更新: · カタログのバージョン 2026.10.02