# GHSA-r75f-5x8p-qvmc

Published articles for GHSA-r75f-5x8p-qvmc.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CVE-2026-42208: Targeted SQL injection against LiteLLM's authentication path discovered 36 hours following vulnerability disclosure

DevFeed: [CVE-2026-42208: Targeted SQL injection against LiteLLM's authentication path discovered 36 hours following vulnerability disclosure](<https://devfeed.tech/articles/cve-2026-42208-targeted-sql-injection-against-litellm-s-authentication-path-discovered-36-hours-following-vulnerability-disclosure-53210.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure>)

Author: Michael Clark

Published: 2026-04-27T00:00:00Z

Content type: news

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [litellm](<https://devfeed.tech/topics/litellm.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Prisma](<https://devfeed.tech/topics/prisma.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai-gateway-security](<https://devfeed.tech/tags/ai-gateway-security.md>), [ai-infrastructure-security](<https://devfeed.tech/tags/ai-infrastructure-security.md>), [api-key-exposure](<https://devfeed.tech/tags/api-key-exposure.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud-credential-theft](<https://devfeed.tech/tags/cloud-credential-theft.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [critical](<https://devfeed.tech/tags/critical.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-42208](<https://devfeed.tech/tags/cve-2026-42208.md>), [cybersecurity-threat-analysis](<https://devfeed.tech/tags/cybersecurity-threat-analysis.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [ghsa-r75f-5x8p-qvmc](<https://devfeed.tech/tags/ghsa-r75f-5x8p-qvmc.md>), [litellm-security-flaw](<https://devfeed.tech/tags/litellm-security-flaw.md>), [litellm-vulnerability](<https://devfeed.tech/tags/litellm-vulnerability.md>), [llm](<https://devfeed.tech/tags/llm.md>), [llm-gateway](<https://devfeed.tech/tags/llm-gateway.md>), [llm-proxy-security](<https://devfeed.tech/tags/llm-proxy-security.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [postgresql-injection](<https://devfeed.tech/tags/postgresql-injection.md>), [pre-auth-sql-injection](<https://devfeed.tech/tags/pre-auth-sql-injection.md>), [prisma](<https://devfeed.tech/tags/prisma.md>), [query](<https://devfeed.tech/tags/query.md>), [research](<https://devfeed.tech/tags/research.md>), [sql-injection](<https://devfeed.tech/tags/sql-injection.md>), [sql-injection-attack](<https://devfeed.tech/tags/sql-injection-attack.md>), [sysdig-threat-research](<https://devfeed.tech/tags/sysdig-threat-research.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-exploitation-timeline](<https://devfeed.tech/tags/vulnerability-exploitation-timeline.md>)

### AI overview

Sysdig Threat Research reports targeted exploitation of CVE-2026-42208, a critical pre-authentication SQL injection in LiteLLM. The activity began 36 hours and seven minutes after global disclosure and targeted database tables containing API keys, provider credentials, and environment configuration, but no confirmed compromise was observed.

### Source excerpt

Critical vulnerability CVE-2026-42208 exposes LiteLLM to pre-auth SQL injection, enabling attackers to extract API keys and credentials. Sysdig analysis reveals targeted exploitation within 36 hours of disclosure.