{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49468.json"
      }
    ],
    "title": "litellm: LiteLLM: Authentication Bypass via Host Header Injection",
    "tracking": {
      "current_release_date": "2026-06-30T03:48:47+00:00",
      "generator": {
        "date": "2026-06-30T03:48:47+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-49468",
      "initial_release_date": "2026-06-22T20:37:14.494000+00:00",
      "revision_history": [
        {
          "date": "2026-06-22T20:37:14.494000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-25T09:27:35+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:48:47+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Exploit Intelligence",
                "product": {
                  "name": "Exploit Intelligence",
                  "product_id": "exploit_intelligence",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:exploit_intelligence:0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Exploit Intelligence"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2",
                  "product_id": "red_hat_ansible_automation_platform_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform 2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "product": {
              "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_id": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/vulnerability-analysis-rhel9?repository_url=registry.redhat.io/exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "product": {
              "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_id": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "product": {
              "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
              "product_id": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/lightspeed-chatbot-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-llama-stack-core-rhel9",
            "product": {
              "name": "rhoai/odh-llama-stack-core-rhel9",
              "product_id": "rhoai/odh-llama-stack-core-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-llama-stack-core-rhel9?repository_url=registry.redhat.io/rhoai/odh-llama-stack-core-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-mlflow-rhel9",
            "product": {
              "name": "rhoai/odh-mlflow-rhel9",
              "product_id": "rhoai/odh-mlflow-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-mlflow-rhel9?repository_url=registry.redhat.io/rhoai/odh-mlflow-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
            "product": {
              "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
              "product_id": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-trustyai-garak-lls-provider-dsp-rhel9?repository_url=registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence",
          "product_id": "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
        },
        "product_reference": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "relates_to_product_reference": "exploit_intelligence"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
        },
        "product_reference": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9"
        },
        "product_reference": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
        },
        "product_reference": "rhoai/odh-llama-stack-core-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9"
        },
        "product_reference": "rhoai/odh-mlflow-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
        },
        "product_reference": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-49468",
      "cwe": {
        "id": "CWE-290",
        "name": "Authentication Bypass by Spoofing"
      },
      "discovery_date": "2026-06-22T21:01:03.552993+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2491520"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in LiteLLM, a proxy server (AI Gateway) used to call Large Language Model (LLM) APIs. A remote attacker could exploit a Host-header parsing vulnerability in the proxy authentication layer. By sending a crafted Host header, an attacker could gain unauthenticated access to protected management routes, potentially leading to full system compromise.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "litellm: LiteLLM: Authentication Bypass via Host Header Injection",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "The vulnerability is rated with Important severity due to the limited attack surface in our default deployment configuration.\n\nWhile the affected images ship with a vulnerable version of litellm, the specific vulnerability is restricted solely to proxy management-route authentication. By default, these images do not start the LiteLLM proxy server. Instead, the default entrypoints are configured to run OGX, the MLflow server (with the AI Gateway disabled), Garak evaluation jobs, or Lightspeed/Llama Stack APIs. The proxy auth bypass is not reachable unless an administrator separately deploys litellm --config from the container.\n\nFor Red Hat OpenShift AI and Ansible Automation Platform products, the severity has been set to low since these products include litellm as a dependency in some images but do not run the LiteLLM proxy in default configurations, hence the vulnerable code path is not exposed.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-49468"
        },
        {
          "category": "external",
          "summary": "RHBZ#2491520",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491520"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-49468",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49468"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-49468",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49468"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/releases/tag/v1.84.0",
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.84.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w",
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w"
        }
      ],
      "release_date": "2026-06-22T20:37:14.494000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "To mitigate the risk of unauthenticated access, restrict network access to the LiteLLM proxy's management routes. Configure network firewalls or security groups to permit inbound connections only from trusted internal networks. This operational control limits the exposure of vulnerable endpoints to unauthorized external access. If the LiteLLM proxy is deployed behind a load balancer or API gateway, ensure these components are configured to strictly validate and sanitize the HTTP Host header before forwarding requests.",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
          ]
        },
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        }
      ],
      "title": "litellm: LiteLLM: Authentication Bypass via Host Header Injection"
    }
  ]
}