THREAT OPS › Threat News › [GHSA] GHSA-hx8v-g79f-8w5f (medium) — LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
[GHSA] GHSA-hx8v-g79f-8w5f (medium) — LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
GHSA-hx8v-g79f-8w5f Severity: medium CVE: CVE-2026-59823
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_config` request body, bypassing the existing parameter gu
Indicators of compromise
- CVE-2026-59823cve
Original source: https://github.com/advisories/GHSA-hx8v-g79f-8w5f