Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-89032— BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer

Quick assessment

Affected
BerriAI litellm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BerriAI 的 LiteLLM 在 1.101.0-rc.1 版本之前存在一个租户隔离绕过漏洞,该漏洞位于语义缓存层。攻击者可以通过利用 函数与 函数之间元数据键的不匹配,使已认证的用户读取其他租户的缓存响应。拥有有效虚拟密钥的攻击者可以在受影响的端点(例如 和 )上提交语义相似的提示,从而获取包含其他租户个人可识别信息、财务数据或源代码的缓存响应。此外,攻击者还可以通过向不同主体返回缓存的 或 负载,导致代理式前端以受害者身份自动执行攻击者提供的工具调用。

CVSS 7.7 · High EPSS 0.27% · P18

Affected Version Matrix 1

VendorProduct Version RangeStatus
BerriAI litellm < 1.101.0-rc.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89032

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer
Source: CVE Program / CVE List V5
Vulnerability Description
BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes such as /v1/responses and /bedrock/* to retrieve cached responses containing other tenants' personally identifiable information, financial data, or source code, and can cause agentic front-ends to auto-execute attacker-supplied tool calls under victim credentials by returning cached function_call or tool_calls payloads to a different principal.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
BerriAI litellm 0 ~ 1.101.0-rc.1 -

II. Public POCs for CVE-2026-89032

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89032

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-89032 (2)

Vendor Advisories for CVE-2026-89032 (1)

Vendor Pages for CVE-2026-89032 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89032

No comments yet


Leave a comment