CVE-2026-59823: LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the
proxy’s outbound request to a host of their choosing by smuggling an api_base inside the
user_config request body, bypassing the existing parameter guard.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-59823 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →