StackRadar

CVE-2026-12795

High

Advisory

Published 21 Jun 2026In the index since 11 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
None
affected package

LiteLLM: SSO Debug Flow Has Improper Authentication

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
litellmpypi1.50.2, 1.51.3, 1.58.2, 1.60.2+7 moreno fix listed11
OSV records
GHSA-j37q-q7p9-vpwm

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
litellm@1.75.5
no fix listed

Open the chart page →

4,292
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
no fix listed

Open the chart page →

20,900
csghubcsghubVerified publisher2.4.32 of 34See more

csghub csghub 2.4.3

2 of the 34 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
no fix listed
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
litellm@1.81.1
no fix listed

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
no fix listed
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
no fix listed

Open the chart page →

11,335
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
no fix listed

Open the chart page →

19,224
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
litellm@1.80.0
no fix listed

Open the chart page →

8,405
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
litellm@1.80.5
no fix listed

Open the chart page →

4,749
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed

Open the chart page →

9,607
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-12795.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
litellm@1.64.1
no fix listed

Open the chart page →

4,499

Container images carrying it

11 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
no fix listed
3
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
litellm@1.80.0
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
litellm@1.81.1
no fix listed
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
no fix listed
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
no fix listed
1
vabene1111/recipes:2.3.50f8d061895e9
litellm@1.64.1
no fix listed
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
litellm@1.75.5
no fix listed
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
litellm@1.80.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.