๐Ÿ” CVE Alert

CVE-2026-89032

HIGH 7.7

BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes such as /v1/responses and /bedrock/* to retrieve cached responses containing other tenants' personally identifiable information, financial data, or source code, and can cause agentic front-ends to auto-execute attacker-supplied tool calls under victim credentials by returning cached function_call or tool_calls payloads to a different principal.

CWE CWE-863
Vendor berriai
Product litellm
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for berriai litellm

Be the first to know when new high vulnerabilities affecting berriai litellm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

BerriAI / litellm
0 < 1.101.0-rc.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/BerriAI/litellm/releases/tag/v1.101.0-rc.1 github.com: https://github.com/BerriAI/litellm/pull/39590 github.com: https://github.com/BerriAI/litellm/commit/16db51e2cfc28e02bd460481e634a8403ea9265e vulncheck.com: https://www.vulncheck.com/advisories/berriai-litellm-rc-1-tenant-isolation-bypass-via-semantic-cache-layer

Credits

Tanguy Snoeck