StackRadar

CVE-2026-35030

Critical

Advisory

Published 3 Apr 2026In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.4
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

LiteLLM: Authentication bypass via OIDC userinfo cache key collision

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
litellmpypi1.50.2, 1.51.3, 1.58.2, 1.60.2+8 more1.83.012
OSV records
GHSA-jjhc-v7c2-5hh6
Also known as
PYSEC-2026-390

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
litellm@1.75.5
1.83.0

Open the chart page →

4,292
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
1.83.0

Open the chart page →

20,900
csghubcsghubVerified publisher2.4.32 of 34See more

csghub csghub 2.4.3

2 of the 34 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
1.83.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
litellm@1.81.1
1.83.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
1.83.0
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
1.83.0

Open the chart page →

11,335
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
1.83.0

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
1.83.0

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
1.83.0

Open the chart page →

19,224
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
litellm@1.80.0
1.83.0

Open the chart page →

8,405
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
litellm@1.80.5
1.83.0

Open the chart page →

4,749
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
1.83.0

Open the chart page →

9,607
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
litellm@1.64.1
1.83.0

Open the chart page →

4,499
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-35030.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
litellm@1.82.3
1.83.0

Open the chart page →

5,201

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/ai-agent:0.0.16545dac92173
litellm@1.50.2
1.83.0
3
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
litellm@1.80.0
1.83.0
1
langgenius/dify-api:1.0.0066035f93856
litellm@1.61.6
1.83.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
litellm@1.82.3
1.83.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
litellm@1.60.2
1.83.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
litellm@1.81.1
1.83.0
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
litellm@1.60.4
1.83.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
litellm@1.51.3
1.83.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
litellm@1.58.2
1.83.0
1
vabene1111/recipes:2.3.50f8d061895e9
litellm@1.64.1
1.83.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
litellm@1.75.5
1.83.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
litellm@1.80.5
1.83.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.