StackRadar

CVE-2026-12770

Medium

Advisory

Published 21 Jun 2026In the index since 11 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
None
affected package

LiteLLM: Admin Key Handler Has Improper Authorization

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
litellmpypi1.50.2, 1.51.3, 1.58.2, 1.60.2+2 moreno fix listed6
OSV records
GHSA-6qr3-3g89-m4jj

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
no fix listed

Open the chart page →

20,900
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
no fix listed

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
no fix listed
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
no fix listed

Open the chart page →

11,335
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
no fix listed

Open the chart page →

19,224
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12770.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607

Container images carrying it

6 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed
3
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
no fix listed
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
no fix listed
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.