Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-59822: BerriAI LiteLLM

BerriAI LitelLM在MCP流式HTTP端點中包含一個不適當的認證弱點,可以讓一個未經認證的攻擊者使用任意的Bearer令牌來建立經過認證的MCP會議。

CISA (English)

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

廠商
BerriAI
產品
LiteLLM
漏洞
BerriAI LiteLLM Improper Authentication Vulnerability
加入日期
2026年9月2日
CISA 修補期限(美國聯邦機關)
2026年9月16日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-287, CWE-306

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02